Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

What is best way to setup WIndows XP and WIndows 7 Desktop's to have non Admin users not see C:\ etc

Posted on 2010-08-25
7
Medium Priority
?
285 Views
Last Modified: 2012-05-10
For an environment that has a Windows Server 2003 SBS and a Mix of WIndows XP and WIndows 7 Professional Desktops I was wondering the best way to do the following:

1) Setup the Desktops to have user (non admin accounts) such that the user's can only see and read/write to their standard Documents, Pictures, Music and Videos folders but not C:\ or other non standard directories.   The users will not even be able to see the non standard directores on their PCs.

The Users will also have their own Folders on the Server via a few Network mapped shared folders on the Server.

As mentioned, I need to know for both Windows XP Pro and Windows 7 Pro desktops.

Thanks
0
Comment
Question by:rdwolf
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
7 Comments
 
LVL 6

Expert Comment

by:fluk3d
ID: 33521348
You would need to modify the ACL on those directories to include the users that need access to them. By default everyone but logged in user and system/domain admin have access.
0
 
LVL 1

Expert Comment

by:Dymer2
ID: 33521693
It is not possible to hide C: and other directories thats part of the system. It is possible to make them read only (via permissions) but invisible, no.
0
 
LVL 2

Expert Comment

by:Juliancito
ID: 33521969
With Actgive Directory Domain and GPO you can do what u want: Create Domain Users and put the PC into domain.
Logon with domain non admin users in desktops
Create an OU and put the users there
Create a GPO for that OU and look for thouse Polices!
You can hide C: D: etc!
You restringe then to their User directoory (home)

GPO is a wide thing to expose here
 
0
Concerto's Cloud Advisory Services

Want to avoid the missteps to gaining all the benefits of the cloud? Learn more about the different assessment options from our Cloud Advisory team.

 
LVL 6

Accepted Solution

by:
zkrieger earned 1000 total points
ID: 33521976
you cannot prevent access to the folders, but you can lock down the system and hide them, etc.

this is all done through group policy. since you are in a domain, you will use domain policy.
the only thing you really need to be aware of is that in order to set policy for XP and Windows 7, you will need 2 computers to work from with the administrative tools installed as well as the group policy tools installed. this is because when you edit policy from a windows XP workstation, those policies do not work for windows 7.

http://technet.microsoft.com/en-us/windowsserver/bb310732.aspx
is microsoft's group policy site.

what you are asking for is very broad. its not really a question at all. you are asking for someone to design your group policy for you. there are about 10,000 what ifs in that.

to set the users as only users, just give them domain accounts, not local accounts. as long as you dont put them in any groups they will not have any rights.

to prevent the C: drive from being visable, you edit the domain policy for the computers and set it

the specific location is "User Configuration" > " Administrative Templates" > "Windows Components" > "Windows Explorer"
then look for the key " Prevent access to drives from My Computer"
Add the C: drive.

save the policy and apply it to the active directory container where you have your user accounts stored. be aware, this means you will need another container for different users who will not get this policy.


again i stress, you are not asking a question, rather you are asking for a domain administrator.
0
 
LVL 6

Assisted Solution

by:fluk3d
fluk3d earned 1000 total points
ID: 33521982
0
 
LVL 6

Expert Comment

by:zkrieger
ID: 33522065
edit to the above:
you edit the domain policy for the users. not the computers.  
0
 

Author Closing Comment

by:rdwolf
ID: 33577244
Thanks for your help.  I realize my question was too wide in scope but I was only looking for some tips to get started and not someone to design my GPOs etc..  The info. provided was very helpful.

Thanks
0

Featured Post

The Eight Noble Truths of Backup and Recovery

How can IT departments tackle the challenges of a Big Data world? This white paper provides a roadmap to success and helps companies ensure that all their data is safe and secure, no matter if it resides on-premise with physical or virtual machines or in the cloud.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

The recent Microsoft changes on update philosophy for Windows pre-10 and their impact on existing WSUS implementations.
When you try to extract and to view the contents of a Microsoft Update Standalone Package (MSU) for Windows Vista, you cannot extract the files from the MSU. Here we are going to explain how to extract those hotfix details without using any third pa…
This Micro Tutorial will teach you how to change your appearance and customize your Windows 7 interface to your unique preference. This will be demonstrated using Windows 7 operating system.
This Micro Tutorial will give you basic overview of the control panel section on Windows 7. It will depth in Network and Internet, Hardware and Sound, etc. This will be demonstrated using Windows 7 operating system.

721 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question