restrict network drive at computer

Posted on 2010-01-07
Last Modified: 2012-05-08
Within my network users have access to a specific network drive, ie:  \\server\share via login script which assigns that drive as "F:".  In one specific Computer OU, I want to remove access to that share/drive, but users need to access this drive everywhere else in the network when they login.  Is there a GPO that I can add to that OU to keep people from accessing that network share while using a specific group of computers?  
Question by:lancecurwensville
    LVL 59

    Accepted Solution

    You would need to setup Group Policy loopback processing. I believe this should restrict the logon script.
    LVL 19

    Assisted Solution

    Ok, so basically, regardless of the user account, you just want to stop ANY users that are logged on to a SPECIFIC set of computers from accessing the F:\ drive?

    If so, you should separate all the computers in to their own OU.

    Then link a loopback policy to that OU only (just a normal policy, and ENABLE the setting Comp Config > Admin Templates > System > Group Policy > "Enable User group policy loopback processing" in REPLACE mode.).

    Along with the above setting, add a log on script that removes the mapped drive or something. (i.e. net use F: /delete)

    This will ensure that the script runs whenever ANY user logs on to ANY computer that is within the OU the policy is linked to.

    I'm not sure if simply removing the mapped drive will suffice in your eyes, but I don't think you can really 'lock it down' as such - So it just comes down to whether or not you think the users would be able to either remap the drive manually, or access it via the UNC path or whatever...

    What do you think?

    LVL 33

    Expert Comment

    You may also want to try this technique... see screen shot in link to remove drive letter:
    LVL 8

    Author Closing Comment

    Both of the comments were dead on.

    Featured Post

    How to improve team productivity

    Quip adds documents, spreadsheets, and tasklists to your Slack experience
    - Elevate ideas to Quip docs
    - Share Quip docs in Slack
    - Get notified of changes to your docs
    - Available on iOS/Android/Desktop/Web
    - Online/Offline

    Join & Write a Comment

    You might have come across a situation when you have Exchange 2013 server in two different sites (Production and DR). After adding the Database copy in ECP console it displays Database copy status unknown for the DR exchange server. Issue is strange…
    The recent Microsoft changes on update philosophy for Windows pre-10 and their impact on existing WSUS implementations.
    This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…
    This tutorial will show how to configure a single USB drive with a separate folder for each day of the week. This will allow each of the backups to be kept separate preventing the previous day’s backup from being overwritten. The USB drive must be s…

    730 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    16 Experts available now in Live!

    Get 1:1 Help Now