Lock down terminal service to only allow access to PeachTree

I am in the process of setting up PeachTree for an accountant on a terminal server.   I created a new OU for the user and via the GP for that OU have been able to lock down the desktop, explorer, and several other things.  Basically from the desktop the user can't do anything but click on the PeachTree icon.  However that is where the problem is at.  Once they open PeachTree, they can then browse the local drives, mapped drives, and also the network.  From a security stand point I don't want them to be able to access anything but the mapped drive where their data files reside.  Any suggestions on how I can lock down the ability to browse from the PeachTree application?  I contacted PeachTree about it, and they indicated there is nothing I can do to the program to resolve the issue.
techhdAsked:
Who is Participating?
 
NJComputerNetworksConnect With a Mentor Commented:
Edit security (NTFS permissions) so that the user does not have access.
0
 
NJComputerNetworksCommented:
0
 
mcsweenSr. Network AdministratorCommented:
If you want them to only be allowed to run Peachtree set the following policy in your GPO

User Config --> Windows Componets --> Terminal Services --> Start a program on connection

With this policy set the user will connect to Terminal Services and Peachtree will launch and they will not even see the desktop or start menu.  When they close Peachtree the terminal server session will end.

How are they browsing the network/local drives once Peachtree is open?

0
Cloud Class® Course: SQL Server Core 2016

This course will introduce you to SQL Server Core 2016, as well as teach you about SSMS, data tools, installation, server configuration, using Management Studio, and writing and executing queries.

 
techhdAuthor Commented:
PeachTree has a browse option to locate the database files.  You then get a drop down that gives the drives.  There is also a network browse where it opens the window for mapping a network drive, where I am able to browse the network.

Tomorrow I will try the NTFS permissions for the local drives which might take care of that problem.  I still need a solution that stops them from browsing the network.  Even though they can't browse into folders due to permissions, I don't want them to be able to even see anything on the network like the shares.

0
 
techhdAuthor Commented:
Editing the Security in NTFS, did eliminate the ability to browse the hard drive from within PeachTree.  I am still looking for some suggestions on how I can block the ability to browse the network?
0
 
techhdAuthor Commented:
I was able to find resolution to stop an individual from browsing the network.  I shut off the computer browser service.  I now have the server locked down that even through Peach Tree the individual will not be able to browse anything.
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.