Jaan Posted June 20, 2022 Posted June 20, 2022 Hi all, We have GPOs in place for Windows to hide the c:/ etc. However we have installed Davinci Resolve, unfortunately it can see the C:/ any ideas if this can be hidden. I can find settings within the app to remove it.... but of course i'd need a gpo/reg setting i'm guessing. Cheers
armadillo Posted March 29, 2023 Posted March 29, 2023 Hi all, We have GPOs in place for Windows to hide the c:/ etc. However we have installed Davinci Resolve, unfortunately it can see the C:/ any ideas if this can be hidden. I can find settings within the app to remove it.... but of course i'd need a gpo/reg setting i'm guessing. Cheers Hi, Excuse me for restarting an old thread. Can you let me know what hardware you are running Davinci Resolve on? I hope you have resolved your issue with the c drive.
Jaan Posted March 29, 2023 Author Posted March 29, 2023 Intel i5 8Gb Ram 240 SSD Intel HD Graphics Windows 10 LTSB (1809)
john Posted March 29, 2023 Posted March 29, 2023 Spookily ICT Direct on thr stand have a machine setup for this, if your at BETT do come and speak to them!
Jaan Posted March 29, 2023 Author Posted March 29, 2023 Spookily ICT Direct on thr stand have a machine setup for this, if your at BETT do come and speak to them! I'm not i'm afraid, I wanted to go ahead with it, but can see access and delete from the C: under to "media" tab on the bottom
robk Posted March 29, 2023 Posted March 29, 2023 Worth considering if the end users can actually delete things that would cause problems, assuming they are not running as local admin etc, accessing the C drive shouldnt be quite as concerning as it used to be.
thimon Posted March 29, 2023 Posted March 29, 2023 This. I don’t see the point of hiding C drive. As long as correct permissions are in place, standard users won’t be able to modify anything they shouldn’t.
Jaan Posted March 30, 2023 Author Posted March 30, 2023 well thats the thing, i was able to delete a "drivers" folder we have in the route of C:\
Steve21 Posted March 30, 2023 Posted March 30, 2023 well thats the thing, i was able to delete a "drivers" folder we have in the route of C:\ Assuming that’s a custom folder then? If so set a GPO to lock down the permissions on it as by default it’s allow users to delete it Steve 1
Jaan Posted March 30, 2023 Author Posted March 30, 2023 Assuming that’s a custom folder then? If so set a GPO to lock down the permissions on it as by default it’s allow users to delete it Steve that's a good point, not had my coffee yet. Any pointers on where and which GPO allows me to do that? cheers
Steve21 Posted March 30, 2023 Posted March 30, 2023 We do it two folded We create the folder on all computers via GPO and then set permissions via Computer Configuration > Policies > Windows Settings > Security Settings > File System (Then setting admins only for modify) That way you have the same folder available on all machines to use for things like backgrounds/drivers/scripts etc Steve 1
Jaan Posted March 30, 2023 Author Posted March 30, 2023 Thanks for that. At the risk going off topic here. I suspect we've had these permissions messed with historically. Where is the default settings that defines that "standard" users can't delete non custom files from the C:\ ? I thought it might be in the "default domain policy" GPO. Or is this permission hard coded into the domain user group? Sorry. This is a little bit of a grey area for me. I inherited this domain, so i'm not sure what's vanilla or been poked with a dirty stick. thanks again
Steve21 Posted March 30, 2023 Posted March 30, 2023 Thanks for that. At the risk going off topic here. I suspect we've had these permissions messed with historically. Where is the default settings that defines that "standard" users can't delete non custom files from the C:\ ? I thought it might be in the "default domain policy" GPO. Or is this permission hard coded into the domain user group? Sorry. This is a little bit of a grey area for me. I inherited this domain, so i'm not sure what's vanilla or been poked with a dirty stick. thanks again It’s not domain policy That’s just standard Windows “non-admin” permissions (uac etc) Steve
Roberto Posted March 30, 2023 Posted March 30, 2023 well thats the thing, i was able to delete a "drivers" folder we have in the route of C:\ So either the folder isn't being created with the right permissions or the root of the C drive (which I'd expect the folder to inherit from if no explicit permissions are set) isn't quite right. I'd agree with the people who don't hide the C:\ drive. Not that there's anything wrong with you doing so if your aim is to make things "look tidy" in explorer if you want to, but it's impossible to do so in an utterly reliable way, so if any part of your security or operational reliability relies on your users not finding a way to get into the drive and have a play then you're on a losing bet, so to speak. 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now