techie211 Posted March 3, 2009 Posted March 3, 2009 hey ppl, I have a few users in a lab that can double click 'All Programs' from the Start menu and delete anything in that window. How can I prevent them from deleting anything in the All Programs via gpo? Server=Win2k3 Workstation= WinXP thanks
powdarrmonkey Posted March 3, 2009 Posted March 3, 2009 Take away their membership of the power users and/or administrators groups
techie211 Posted March 3, 2009 Author Posted March 3, 2009 thanks for your reply but that didn't work.
srochford Posted March 3, 2009 Posted March 3, 2009 Check the permissions on the folder (probably c:\documents and settings\all users\start menu\programs) The group "users" should only have read access to that; if that's not the case then that's why they're able to delete stuff and you need to reset it. If users can only read then look at the other groups and find out which groups do have write access; make sure that normal users are not in any of those groups.
superfletch Posted March 6, 2009 Posted March 6, 2009 Any good? GPO Editor | Relevant OU user config admin templates start menu and taskbar prevent changes to taskbar and start menu settings
p858snake Posted March 7, 2009 Posted March 7, 2009 Any good? GPO Editor | Relevant OU user config admin templates start menu and taskbar prevent changes to taskbar and start menu settings I think you will find that is for the start menu display settings and such. 1
bio Posted March 9, 2009 Posted March 9, 2009 Redirected Start Menu in the mandatory profile with appropriate permissions? Indeed this is the way we also have configured it.. works like a charm bio...
K.C.Leblanc Posted March 9, 2009 Posted March 9, 2009 Redirected Start Menu in the mandatory profile with appropriate permissions? You can also set the permissions of local profiles using a GPO.
sippo Posted March 9, 2009 Posted March 9, 2009 Redirected Start Menu in the mandatory profile with appropriate permissions? Thats the easiest way. I like it when the 'know-it-all' students try and be clever, and delete everything from the start menu...log off, then they log back in and its the same!! I've never seen so many confused faces. He he.
superfletch Posted March 12, 2009 Posted March 12, 2009 (edited) Hi folks, This is pretty much what I try to use where possible: "Redirected Start Menu in the mandatory profile with appropriate permissions." I'm happy with the concept of this but I seem to be getting it wrong: Where do you guys keep: Profile: Start Menu: Desktop: What are your AD Settings AS FAR AS where each thing should be? THANKS MF Edited March 12, 2009 by superfletch LOSERS EAT GOATS
oalcock Posted September 1, 2009 Posted September 1, 2009 Locate the source Start Menu Folder on the server, right click on it, go to permissions and choose for the permissions to be set so that only administrators can change the start menu settings. This is assuming you have a network set up like this, if not its recommended for security reasons. If the start menus are connected through local programs and icons, there maybe a script which I don't know I am affraid. Hope that is some help to you!
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now