Gambit Posted May 22, 2007 Posted May 22, 2007 I have now learned that students are finding a way to access the c: drive on the computer, by creating a shortcut and putting c:\. Is there a way to deny creating shortcuts for students? I did a google on this and was not able to find anything on how to block this.
DSapseid Posted May 22, 2007 Posted May 22, 2007 in one of the policys instead of just hiding it restrict them from accessing it.
CyberNerd Posted May 22, 2007 Posted May 22, 2007 I eluded to this in a couple of other posts, but didn't really get an awnser: whats the problem with students accessing c:\ drive with default windows permissions - what is the worst they can do? is windows default file permissions secure? do we need to restrict access? If the windows default file permissions are not secure, rendering the machine trashable, what extra permissions need to be set?
DSapseid Posted May 22, 2007 Posted May 22, 2007 When the kids here logon the only thing they see in my computer is their H drive (home drive) and a floppy if that machine has one in. They do have write access to the C drive but only the program files area as this is needed for some software to run. I think this is important as if they logon to a machine which has SIMS on it they can open some of the files found in Program Files to find confidential info. I am also in the proccess of looking at restricting them from using floppys in the machines that do have them in. We have had the kids here bring in all sorts of little apps from home on USB Pens, email it to themselves to try and get access to the C drive but as yet no success' to my knowledge anyway!
localzuk Posted May 22, 2007 Posted May 22, 2007 you seem to have double posted: http://edugeek.net/index.php?name=Forums&file=viewtopic&p=88229#88229
Gambit Posted May 22, 2007 Author Posted May 22, 2007 yeah sorry about that, first time I hit send it IE timed out, so I refreshed & re-submitted.
snrweb Posted May 22, 2007 Posted May 22, 2007 Don't panic. The GP stops them seeing it but they can type it and some programs will access it anyway. Its not a problem if they only have default permissions set. Ensure that the users don't have increased permissions (such as if Domain Users was a member of the local administrators group)
ZeroHour Posted May 23, 2007 Posted May 23, 2007 Software Restriction policies with SP2 should help with this. If you block execution from a area I believe shortcuts in that area will be effected also.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now