Jump to content

Recommended Posts

  • 5 months later...
Posted
We found that if you go to control panel > network and sharing centre > advance sharing settings and turn off network discovery it will ask you to enter the administrator password before allowing you to access the Network folder.
Posted
if your tech can work out how to remove the rest of it I would be much obliged!

 

Favorites:

 

Windows Registry Editor Version 5.00

 

[HKEY_CLASSES_ROOT\CLSID\{323CA680-C24D-4099-B94D-446DD2D7249E}\ShellFolder]

"Attributes"=dword:a9400100

"PinToNameSpaceTree"=""

 

Libraries:

 

Windows Registry Editor Version 5.00

 

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\{031E4825-7B94-4dc3-B131-E946B44C8DD5}]

[-HKEY_CLASSES_ROOT\CLSID\{031E4825-7B94-4dc3-B131-E946B44C8DD5}]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{031E4825-7B94-4dc3-B131-E946B44C8DD5}]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2112AB0A-C86A-4ffe-A368-0DE96E47012E}]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{491E922F-5643-4af4-A7EB-4E7A138D8174}]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7b0db17d-9cd2-4a93-9733-46cc89022e7c}]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A302545D-DEFF-464b-ABE8-61C8648D939B}]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A990AE9F-A03B-4e80-94BC-9912D7504104}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel]

“{031E4825-7B94-4dc3-B131-E946B44C8DD5}”=-

 

network:

 

Windows Registry Editor Version 5.00

 

[HKEY_CLASSES_ROOT\CLSID\{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}\ShellFolder]

"Attributes"=dword:b0940064

 

 

Some of them will require administrator permissions manually setting on them.

  • Thanks 2
  • 11 months later...
Posted
I was trying to do the same thing. I found here you can make the above settings into an adm file so you can import into group policy so its appears as on off radio buttons. Prooved Very useful for me.
  • Thanks 2
  • 3 months later...
Posted

cheers, i didnt realise there was an up to date thread from literally yesterday on the exact same topic!

 

Ive implemented the custom adm which seems to be working well, so will see how that goes.

 

thaksn

  • 2 months later...
Posted

I have been able to remove the network icon [good news]

 

However I am now trying to find a way to prevent the machine from accepting a UNC path entered into the save/save as box. I have tried the following setting in Group Policy:

 

Computer Configuration/Admin Templates/Network/Link Layer Topology Discovery: Turn on Mapper I/O (LLTDIO) driver: Disabled.

 

Doesn't seem to do the trick.

 

What else can I try?

  • 2 weeks later...
Posted
I was trying to do the same thing. I found here you can make the above settings into an adm file so you can import into group policy so its appears as on off radio buttons. Prooved Very useful for me.

 

This worked for me!! :)

  • 8 months later...
Posted
Raise from the dead, however it is possible to add this to the registry section of a GPO applying to users, at least on the Vista User template GPO's, it works nicely thanks :)
  • 11 months later...
Posted

A student brought a usb with a shortcut to a network UNC path of our applications server (not to any shared folder on it, just the server itself) - they are able to see what folders are shared and now access network browsing through windows explorer. The above along with SRP is not stopping them from doing this - has anyone else come across this problem and knows how to resolve it?

 

Capture.PNG

Posted
no they are not and unfortunately its how I took over the system but its too much a task to now rename them all on every file server, it doesn't address the underlying issue that they can browse network in windows explorer even though the network icon has been removed
Posted

So long as they continue to be unhidden shares they will easily be browsed no matter what you do to prevent it.

 

The only way you can prevent browsing of shares is setting them up as hidden with the $.

Posted

GPO: User Config\Admin Templates\Desktop\Active Directory

 

Set 'maximum size of Active Directory searches' to 0

Set 'Hide Active Directory folder' to hidden

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...