2019 Terminal Server can't get rid of "Opening these file might be harmful" and "We can't verify who created this file."

Anonymous
2024-06-10T19:49:00+00:00

After upgrading from 2012R2 to 2019 for our Citrix Virtual Apps server I'm running into issues with file warnings.

On the Citrix servers profiles are redirected to a network share and handled by Citrix Profile Manager, which sync's and cleans up anything left by folder redirection.

When I'm RDP connected to a TS and launch a shortcut from the task bar I get the Open File-Security Warning. Do you want to open this file? This file is not from the internet. Many more like it where robocalled from the old file server.

When users try to double click a zip file on their network drive they get a different Open File- Security Warnings. Your Internet security settings blocked one or more files from being opened.

Using Group Policy I've added:

-Site to Zone Assignment List

domain1.local 2 - I've also tried 1 but figured 2(trusted) is better

fileserver 2

fileserver.domain1.loacal 2 - Tried adding the file server also.

  • Turn on automatic detection of intranet -enabled

-intranet sites: include all network paths- enabled

-intranet sites include all local sites not listed in others- enabled

  • check for signatures on downloaded programs- disabled
  • HKLM Inclusion list for low file types- ".zip;.rar;.nfo;.txt;.exe;.bat;.com;.cmd;.reg;.msi;.htm;.html;.gif;.bmp;.jpg;.avi;.mpg;.mpeg;.mov;.mp3;.m3u;.wav;.mxl;.map;.xml;.lnk"

-default risk level for file attachments -enabled -low

-do not preserve zone information in file attachments -enabled

Does anyone have any suggestions to clear these messages?

Thanks

Windows for business | Windows Server | Networking | Network connectivity and file sharing

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question. To protect privacy, user profiles for migrated questions are anonymized.

0 comments No comments
{count} votes

4 answers

Sort by: Most helpful
  1. Anonymous
    2024-06-10T19:49:29+00:00

    After upgrading from 2012R2 to 2019 for our Citrix Virtual Apps server I'm running into issues with file warnings.

    On the Citrix servers profiles are redirected to a network share and handled by Citrix Profile Manager, which sync's and cleans up anything left by folder redirection.

    When I'm RDP connected to a TS and launch a shortcut from the task bar I get the Open File-Security Warning. Do you want to open this file? This file is not from the internet. Many more like it where robocalled from the old file server.

    When users try to double click a zip file on their network drive they get a different Open File- Security Warnings. Your Internet security settings blocked one or more files from being opened.

    Using Group Policy I've added:

    -Site to Zone Assignment List

    domain1.local 2 - I've also tried 1 but figured 2(trusted) is better

    fileserver 2

    fileserver.domain1.loacal 2 - Tried adding the file server also.

    • Turn on automatic detection of intranet -enabled

    -intranet sites: include all network paths- enabled

    -intranet sites include all local sites not listed in others- enabled

    • check for signatures on downloaded programs- disabled
    • HKLM Inclusion list for low file types- ".zip;.rar;.nfo;.txt;.exe;.bat;.com;.cmd;.reg;.msi;.htm;.html;.gif;.bmp;.jpg;.avi;.mpg;.mpeg;.mov;.mp3;.m3u;.wav;.mxl;.map;.xml;.lnk"

    -default risk level for file attachments -enabled -low

    -do not preserve zone information in file attachments -enabled

    Does anyone have any suggestions to clear these messages?

    Thanks

    0 comments No comments
  2. Anonymous
    2024-06-11T15:01:44+00:00

    Hello,

    Based on our understanding of your issue, we suggest you refer to the following method:

    Search inetcpl.cpl in the Windows search bar to open it, and find the custom level in the security column.

    Find and check the option shown below.

    Best regards

    Zunhui

    0 comments No comments
  3. Anonymous
    2024-06-11T16:24:55+00:00

    This is not possible individually. How can this be set by Group Policy in a domain?

    Thanks for your suggestion. I'll start looking for a way to implement this with registry maybe.

    0 comments No comments
  4. Anonymous
    2024-06-18T13:27:38+00:00

    anyone?

    0 comments No comments