Hi all,
I want to set up what may be unusual. We are a town with an Active Directory domain. On that domain is a file server holding video files. I would like to build a PC and create a domain user and give them READ ONLY access to this folder on the FS. That's easy, I can handle that part.
However, on the PC this user will be logging into, I would lie to completely lock it down so that they really can't do anything except use file explorer to access the network share. I don't want them to do a damn thing otherwise. They will need to be able to go to the share, copy files from it, use a USB drive, and that's it. Nothing else.
I don't know how to do such things. Domain GPO? Local PC GPO? Either way, there is SO MUCH in there, it seems rather silly to try to go through everything one item at a time. Is there a faster, better method? If not, what should I be looking for and disabling in there?
I'd appreciate any advice. Thanks!