Solved

Disable access to or not view Drive C: SBS2011 / servers - via group policy

Posted on 2014-04-21
7
579 Views
Last Modified: 2014-05-01
Hi All

Our client has asked us to disable users access / or hide drive C: on four of their company servers.

Two of them are server 2008 r2, one of them is a server 2003 unit and the final one is their SBS2011 server. - these machines are TS'ed into (except sbs 2011)

We wish to employ this via group policy.

Ideally we want this to apply just to the servers, but if it applies to the whole client group also that's fine.

I appreciate this can be achieved via hiding drive C and that's fine also.

I have found lots of methods to achieve this with server 2003 but not for sbs2011.

Any help would be appreciated.

Thank you
Andy
0
Comment
Question by:AndyKeen
  • 4
  • 3
7 Comments
 
LVL 28

Accepted Solution

by:
Michael Pfister earned 500 total points
ID: 40014235
If non-admins aren't using RDP to access the SBS, I'd just leave it.
Besides that its the same procedure for 2003 or SBS.

Since it has side effects in some applications when you prevent access to C:, I'd rather limit the GPO just to the servers that require it.

Its a user GPO so if you link it to the server's OU, you need turn on loopback processing.
http://support.microsoft.com/kb/231287/en-us
0
 
LVL 28

Expert Comment

by:Michael Pfister
ID: 40014238
0
 
LVL 1

Author Comment

by:AndyKeen
ID: 40014268
Hi Mpfister

Thanks for the info and feedback.

Is it not possible to 'hide' drive C from the users - how would this prevent programs from working.

I can see in various articles there are methods for hiding certain / all drives from view.

Are you saying that 'hiding' drives would have an adverse effect on programs also
Thanks
0
Control application downtime with dependency maps

Visualize the interdependencies between application components better with Applications Manager's automated application discovery and dependency mapping feature. Resolve performance issues faster by quickly isolating problematic components.

 
LVL 28

Expert Comment

by:Michael Pfister
ID: 40014289
You can use the GPO setting under User Configuration -> Administrative Templates -> Windows Components -> Hide these specified drives from "My Computer" and "Prevent access to drives from "My Computer" do disable C:.

But I've experienced error messages in some programs when users access an "Open file" dialog that defaults to C:\Users... The user gets an error message that its unable to access C:. If they click "ok" they can contine to browse to a different drive, but its a bit confusing.

Still access to C: is not really blocked, because Windows itself and installed programs wouldn't work anymore.
0
 
LVL 1

Author Comment

by:AndyKeen
ID: 40015023
Thanks Mpfister for the info and insight - I shall let me customer know and he can make a more informed choice.
0
 
LVL 1

Author Comment

by:AndyKeen
ID: 40034045
Thanks for the help Mpfister - my customer decided not to go with hiding drive C:
0
 
LVL 1

Author Closing Comment

by:AndyKeen
ID: 40034046
Quick and Concise - excellent
0

Featured Post

Is Your Active Directory as Secure as You Think?

More than 75% of all records are compromised because of the loss or theft of a privileged credential. Experts have been exploring Active Directory infrastructure to identify key threats and establish best practices for keeping data safe. Attend this month’s webinar to learn more.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Introduction At 19:33 (UST) on Tuesday 21st September the long awaited email arrived with the subject title of “ANNOUNCING THE AVAILABILITY OF WINDOWS SBS 7 PREVIEW”.  It was time to drop whatever I was doing and dedicate as much bandwidth as possi…
This guide is intended to provide step by step instructions on how to migrate from Small Business Server 2003 to Small Business Server 2011. NOTE: This guide has been written using the preview version of SBS2011 therefore some of the screens may …
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …
Internet Business Fax to Email Made Easy - With  eFax Corporate (http://www.enterprise.efax.com), you'll receive a dedicated online fax number, which is used the same way as a typical analog fax number. You'll receive secure faxes in your email, f…

863 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

23 Experts available now in Live!

Get 1:1 Help Now