Jump to content

Recommended Posts

Posted

I am looking at the policy

 

User Config -> Policies -> Admin Templates -> System -> Prevent access to the command prompt.

 

which states:Prevents users from running the interactive command prompt, Cmd.exe. This setting also determines whether batch files (.cmd and .bat) can run on the computer.

 

If you enable this setting and the user tries to open a command window, the system displays a message explaining that a setting prevents the action.

 

Note: Do not prevent the computer from running batch files if the computer uses logon, logoff, startup, or shutdown batch file scripts, or for users that use Remote Desktop Services.

 

I have enabled the policy and chosen No to Disable the command prompt script processing also?

 

Should this cause any problems with user login scripts that set drive mappings etc?

Posted

You don't say what server version your on but on windows server 2003 you might find it easier to set up path rules for bat and cmd blocking to prevent them from being run.

Find this under

user configuration-windows settings-security settings- software restriction policies- additional rules
rather than blocking them via the admin templates-system

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...