Create a Group policy object and configure following setting on that to block disk C:
User Configuration \ Administrative Templates \ Windows Components \ Windows Explorer. Then on the right side under Setting, double click on Prevent access to drives from My Computer.
Then, Select Enable then under Options from the drop down menu you can restrict a certain disk.
Then you can link that GPO into the OU where your PCs are located.
To restrict desktop, You can do like following,
- Create a Group Policy Object, go to Computer Configuration > Policy > Windows Settings > Security Settings > File System
- Right click and add %userprofile%\Desktop ( or another different folders that you want to restrict)
- Then Specify the permissions