Hi all, my 2 cents towards this. I have been playing with this for a week or so now. I first tried 1803 and blocked cortana via app locker. This seemed to work except for the double click nuisance. After deployment to machines I had the full screen greyed out issue ( you can navigate via tab key though if you have noticed )
My tinkering with applocker eventually broke my test machine which would eventually not even boot. I have now gone to Windows 10 2019 LTSC which strips all the apps and used user based SRP to block Cortana & the security center notification ( you can use GPO to hide a lot of the security center )
This "so far" has seemed to work on 2 test machines.. We need search function disabled as students can browse UNC paths although NTFS permissions will deny them but I do not like the fact that they can browse SYSVOL and attempt to make a connection to servers by just typing in \\hostname and run System32 commands from the search ( e.g gpupdate , cscript ) although access to the C drive is blocked via other GPO.
I may further this by using SRP to disallow most system32 commands as the old create a shortcut hack is still viable for the kids who know what they are doing..