I have setup a new GPO and assigned it to an OU. This GPO redirects everyone who is a member of the global security group "GG-All Staff" desktop to a shared location (\\file01\desktop). I have then set up ntfs permissions on that share to allow only read access to \\file01\desktop. The reason for this setup is because I want all the users of gg-all staff to see the same desktop and not be able to edit the desktop (add and remove icons). This is not working the way it should because all users in the gg-all staff group are seeing the correct desktop (from the shared location) but are able to add and remove icons, which ofcourse is then being displayed on everyone elses desktop. I have made sure that only read access is setup on the share. Now the intresting this is that if I go into the ntfs permissions of the share (desktop) and add an individule to the permissions (who is also a member of the "gg-all staff" group) and give this individule read only permissions to the desktop share, it works for him. I mean he sees the correct desktop but also he is unable to edit or update it.
This has really confused me, any help would be great.
Many thanks to you all