Restricting local drives with GP
hi all,
i wondered if give me tips or share experience using group policy restrict local drives on client workstations. i'm starting try across our mixed environment , finding has few quirks.
by way of background, have mixed estate of xp, vista , 1 or 2 win7 desktop workstations, laptops, tablet pcs , virtual desktop clients. use gp apply configuration security , standardisation purposes, we're having thorough review of it.
when introduced windows vista , migrated users across, applied gp restrict c drive. policy settings configured follows:
user configuration > administrative templates > windows components > windows explorer - "hide these specified drives in computer" , "prevent access drives computer". both set "enabled" option "restrict c drive only".
we've found works quite on vista, there few problems it. we've begun test-deploying same policy xp though we're encountering more problems.
these sort of things we've been finding:
and there variety of other small glitches. nothing perhaps major, few things cause lot of annoyance if deployed widely.
it seems problem caused 'prevent access' setting rather 'hide drive' one. hide drive s says prevent access interfere calls try , view path starting c:\, if path part of user profile.
what want find out if else has found ways of alleviating problems user's profile , been able deploy setting prevent access c drive. know go 'soft' option of not using the prevent access , using hide drives , seems easy round (type 'c:' run box, example) not worth using.
thanks reading,
al
Windows Server > Group Policy
Comments
Post a Comment