Jump to content

Prevent Users Going to C: and or AppData from Start Menu


Recommended Posts

Posted

Hello, we have found that we are going to need to try to prevent users from accessing their app data folder and writing files.

You an absolutely prevent users from going to these folders using File Explorer, but is there a way to prevent users from simply typing C: on their keyboard bringing up search and allowing access?

 

Thanks.

Guest Guest
Posted
Yep, in group policy under user configuration, Windows components, file explorer you should see a policy under the lines of Prevent access to these specified drives.
  • 2 weeks later...
Posted

We did use to prevent the Start menu search function from working by blocking it with AppLocker, but I'm not sure that's viable any longer. The Start menu search functionality used to just be handled by the Cortana app, so blocking that app with AppLocker was a slightly cludgy way to close this sort of thing off, but I believe the Start menu search functions are now handled directly by Explorer itself.

 

Your next steps will probably depend on the specifics of what you're rrying to combat. If it's a problem with people running random software from within AppData, you should be able to cover that off with AppLocker, whilst still allowing for the likes of Teams which I believe need to be run from there as well.

Posted

Sorry I meant to post this on Friday, but it seems like I didn't hit the button...

 

This is a strange one and I don't envy your task.

 

I am surprised this post hasn't attracted more 'it's all permissions, what harm can they do?' responses...

 

I have found myself in this situation and unfortunately never got anywhere. As you found out, I deployed the above GPO and found that it creates some issues. We also used 'Hide these drives' but it didn't seem to work if they could just type in C: and it would open...

 

This creates some errors including for us, using a 'local' version of Office when saving files it still looks for local folders and produces 2 error messages that need to be clicked through which can be confusing.

 

We don't use OneDrive or Teams but with that GPO you pretty much seem to need all local user folders accessed by the user redirected as no local folders can be used such as Documents etc. (and redirecting Appdata is apparently a world of pain)....

 

I tried various other ways to disable the search function instead, SRP, Applocker (neither of which worked in our set-up for some reason), the only thing that blocked it entirely was renaming the Cortana folder, however this produces a Start Menu anomaly that means you have to click it twice or it is dulled and not able to be clicked on (although it has been mentioned that it is not controlled by Cortana in recent Windows 10 versions, so that might not help you but we're on LTSC).

  • 1 month later...
Posted
Hello, we have found that we are going to need to try to prevent users from accessing their app data folder and writing files.

You an absolutely prevent users from going to these folders using File Explorer, but is there a way to prevent users from simply typing C: on their keyboard bringing up search and allowing access?

 

Thanks.

 

Currently come across this same issue too! All GPOs in place to hide C: drive (cannot restrict as using OneDrive client like yourself) within File Explorer, but if Windows Search is enabled use can just type C: and obtain access to the C: Drive.

 

 

Sorry I meant to post this on Friday, but it seems like I didn't hit the button...

 

This is a strange one and I don't envy your task.

 

I am surprised this post hasn't attracted more 'it's all permissions, what harm can they do?' responses...

 

I have found myself in this situation and unfortunately never got anywhere. As you found out, I deployed the above GPO and found that it creates some issues. We also used 'Hide these drives' but it didn't seem to work if they could just type in C: and it would open...

 

This creates some errors including for us, using a 'local' version of Office when saving files it still looks for local folders and produces 2 error messages that need to be clicked through which can be confusing.

 

We don't use OneDrive or Teams but with that GPO you pretty much seem to need all local user folders accessed by the user redirected as no local folders can be used such as Documents etc. (and redirecting Appdata is apparently a world of pain)....

 

I tried various other ways to disable the search function instead, SRP, Applocker (neither of which worked in our set-up for some reason), the only thing that blocked it entirely was renaming the Cortana folder, however this produces a Start Menu anomaly that means you have to click it twice or it is dulled and not able to be clicked on (although it has been mentioned that it is not controlled by Cortana in recent Windows 10 versions, so that might not help you but we're on LTSC).

 

We have used AppLocker to block Microsoft.Windows.Search, as well as registry tweak to hide Search from Taskbar, but with later versions of Windows 10 it affects (e.g. blocks) the search facility within File Explorer.

 

Customising Windows 10 is certainly one step forwards, and 10 steps back at times! As in, just when you think you have configured a setting just how you require it; by doing so unleashes other stuff! :confused:

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...