C$ read only access?

Is there a way to give users rights to \\computers\c$ but readonly?
F.e. powershell Add-smbhareaccess to c$ is not allowed because it is a default admin share but maybe we could add the users to a specific group which then has only readonly accesss?

J.
janhoedtAsked:
Who is Participating?
 
Scott CConnect With a Mentor Senior Systems EnginerCommented:
No, there isn't.  C$ is an admin share for a good reason....users have NO business mucking around on the root of the C drive.

Create them a share on C if you must, but on another drive is better and give them rights to that share.

Under no circumstances should users be at the roof of C.
1
 
JohnBusiness Consultant (Owner)Commented:
I agree. And there is nothing there a user needs.  Make Users share that people can use for individual files and a Common or like folder for shared documents.
0
 
oBdACommented:
Some sort of HelpDesk access?
You can share C: under a different name (for example "CRO" or "CRO$" - yes, the same folder can be shared multiple times), and leave the Share permissions as Read Only.
Note that this will still not give them NTFS access to folders where they aren't allowed.
0
Simplify Active Directory Administration

Administration of Active Directory does not have to be hard.  Too often what should be a simple task is made more difficult than it needs to be.The solution?  Hyena from SystemTools Software.  With ease-of-use as well as powerful importing and bulk updating capabilities.

 
janhoedtAuthor Commented:
Thanks, I knew that. I explicitly wanted to share c$ but seems not possible.
0
 
JohnBusiness Consultant (Owner)Commented:
Yes, not a good idea at all. Set up proper shares and share those.
0
 
oBdACommented:
The administrative shares are completely controlled by the system. You can only disable them completely (which is usually not recommended), but not change their configuration.
0
 
janhoedtAuthor Commented:
Don't agree at all. I see no reason why some extra users shouldn't have read only to C$. Now shares need to be created which is extra administration. Yes, it s very easy via Powershell but still don't like it.
0
 
janhoedtAuthor Commented:
Do not fully agree of usefullness,  but yes it is not possible
0
 
oBdACommented:
Changing the permissions would be "extra administration", too ...
0
 
janhoedtAuthor Commented:
But then the share stays c$ for everyone and it is clear. Now you need a name and configure it on all devices. Adding users via goo is no work at all.
0
 
janhoedtAuthor Commented:
gpo
0
 
Scott CSenior Systems EnginerCommented:
Glad I could help.
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.