Avatar of GCITech
GCITech asked on

easiest way to disable calculator on a domain user, at AD login. It can stay disabled for other users, if necessary.

I want to rename calc.exe to calc.inop. using the login batch file for the user. (Actually all elementary users use this same user account, so it is being applied to a group)

I added this to their login batch file that pushes shortcuts to desktop:

if exist c:\windows\system32\calc.inop echo Now Exiting && Exit
takeown /F c:\windows\system32\calc.exe
pause
icacls c:\windows\system32\calc.exe /grant empire\administrator:(D,WDAC) /Q
pause
ren c:\windows\system32\calc.exe calc.inop


I added the pauses so I can see where is erroring. Looks like the batch file needs to run elevated. I know about making a shortcut to the batch file, and making it run elevated, but I don't know how to point login to said shortcut. 



Windows Batch* AD Domain* User accounts* Script Task

Avatar of undefined
Last Comment
Andrew Porter

8/22/2022 - Mon
ASKER CERTIFIED SOLUTION
NVIT

Log in or sign up to see answer
Become an EE member today7-DAY FREE TRIAL
Members can start a 7-Day Free trial then enjoy unlimited access to the platform
Sign up - Free for 7 days
or
Learn why we charge membership fees
We get it - no one likes a content blocker. Take one extra minute and find out why we block content.
See how we're fighting big data
Not exactly the question you had in mind?
Sign up for an EE membership and get your own personalized solution. With an EE membership, you can ask unlimited troubleshooting, research, or opinion questions.
ask a question
Andrew Porter

Why wouldn't you just remove NTFS permissions for the calc.exe application instead?
This is the best money I have ever spent. I cannot not tell you how many times these folks have saved my bacon. I learn so much from the contributors.
rwheeler23