Hi,
GPO:
User Configuration > Windows Settings > Security Settings > Softwrae Restriction Policies > Additional Rules
Add a new path rule
\\server2\users$
Disallowed
We also add the profile path
\\server2\profiles$
Disallowed.
just looked at the GPO results for the students pc and it says
Policy Setting
Interactive logon: Number of previous logons to cache (in case domain controller is not available) 0 logons
Software Restriction Policieshide
Enforcement
Policy Setting
Apply software restriction policies to All software files except libraries (such as DLLs)
Apply software restriction policies to the following users All users
Designated File Types
File Extension File Type
ADE Microsoft Office Access Project Extension
ADP Microsoft Office Access Project
BAS BAS File
BAT MS-DOS Batch File
CHM Compiled HTML Help file
CMD Windows NT Command Script
COM MS-DOS Application
CPL Control Panel extension
CRT Security Certificate
EXE Application
HLP Help File
HTA HTML Application
INF Setup Information
INS Internet Communication Settings
ISP Internet Communication Settings
LNK Shortcut
MDB Microsoft Office Access Application
MDE Microsoft Office Access MDE Database
MSC Microsoft Common Console Document
MSI Windows Installer Package
MSP Windows Installer Patch
MST MST File
OCX ActiveX Control
PCD PCD File
PIF Shortcut to MS-DOS Program
REG Registration Entries
SCR SCR File
SHS Scrap object
URL Internet Shortcut
VB VB File
WSC Windows Script Component
Trusted Publishers
Allow the following users to select trusted publishers End users
Before trusting a publisher, check the following to determine if the certificate is revoked None
Software Restriction Policies/Security Levelshide
Policy Setting
Default Security Level Unrestricted
Software Restriction Policies/Additional Ruleshide
Hash Ruleshide
LOGON.BAT; 5 KB; 27/05/2009 12:56:15
File hash 2FE2D2B3483A7C121F8A824CC9824F3C:4417:32771
Security level Unrestricted
Description
Date last modified 16/02/2011 11:10:24
Path Ruleshide
%HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot%
Security Level Unrestricted
Description
Date last modified 15/02/2011 16:23:27
%HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot%*.exe
Security Level Unrestricted
Description
Date last modified 15/02/2011 16:23:27
%HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot%System32\*.exe
Security Level Unrestricted
Description
Date last modified 15/02/2011 16:23:27
%HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir%
Security Level Unrestricted
Description
Date last modified 15/02/2011 16:23:27
H:\ bat
Security Level Disallowed
Description
Date last modified 17/02/2011 12:45:46
H:\ exe
Security Level Disallowed
Description
Date last modified 17/02/2011 12:45:52
H:\*.exe
Security Level Disallowed
Description
Date last modified 15/02/2011 16:58:10
H:\*.exe
Security Level Disallowed
Description
Date last modified 16/02/2011 13:09:21
H:\*bat
Security Level Disallowed
Description
Date last modified 16/02/2011 11:07:06
H:\cmd
Security Level Disallowed
Description
Date last modified 17/02/2011 12:46:28
logon.bat
Security Level Unrestricted
Description
Date last modified 16/02/2011 10:52:11
But the student just rename the bat file and run it
Example is open word then put a scrip command in it then save it as a plane text .
word will then let you save it as a hack.BAT in the home drives
Then run it.
How can we stop them when we use Logon.bat to map printers and map drives?
Any help please....