markesmith Posted July 1, 2006 Posted July 1, 2006 Because on our workstations (XP SP2) it points to the local C: drive and a click of the up arrow and they have left H: and have access to C: I deleted all the shortcuts from the users' home area on the server but when they login again it's recreated. Same for Sample Music. Any ideas?? Many thanks
ITWombat Posted July 1, 2006 Posted July 1, 2006 I don't know if there's a reg hack you could use ut how about creating a short cut of your own and copying it over the default one. It could point to an innocuous share where you want it to be. On more general point it shouldn't matter about the kids getting onto the C: drive if you set the NTFS permissions securely and use software restriction plocies (SRP) to prevent the execution of games and/or malware.
webman Posted July 1, 2006 Posted July 1, 2006 If you use logon scripts, you could add some lines at the end to delete it based on the %USERPROFILE% variable or similar.
tosca925 Posted July 2, 2006 Posted July 2, 2006 In GPO dont give them access to see the C:drive let alone access it.
ITWombat Posted July 2, 2006 Posted July 2, 2006 @tosca Unfortunately the those parts of the admin templates only work for Windows Explorer. Other apps, including some from Microsoft, don't always respect these settings. NTFS ACLs and SRP should always work in all but exceptional cases.
tosca925 Posted July 3, 2006 Posted July 3, 2006 But have you put into into practice ona test OU? I have this in place and as far as i know no one can access the c; drive through any MS software as well as explorer.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now