GPO - restrics access to disk c:\ for users. Allow access for domain administratos to network \\pcname\c$

Eduard Martinenko 111 Reputation points
2020-07-24T11:32:35.893+00:00

What is the proper way to restrict access to system disk to users? But at the same time:

  • Allow the operation system, especially drivers, and already installed software work properly.
  • Allow domain administrators to have access to user's system disks by "\pcname\c$"
Windows for business | Windows Server | User experience | Other
Windows for business | Windows Server | Devices and deployment | Configure application groups
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Anonymous
    2020-07-27T05:34:25.233+00:00

    Hello,

    Thank you for posting here.

    According to your description, as for the GPO to restrict users to access disk C:\, we could have a check whether this GPO is what we want.

    User Configuration > Administrative Templates > Windows Components > Windows Explorer > Prevent access to drives from My Computer. It is set to "Enabled" with the option "Restrict C drive only".

    This similar case is also discussed on our TechNet forum. Below is the link:
    https://social.technet.microsoft.com/Forums/en-US/f0e747b9-8952-46aa-ac4d-0d9ad341f4c8/how-to-restrict-users-to-access-windows-folder-on-local-drive-quotcquot?forum=winserverGP

    For any question, please feel free to contact us.

    Best regards,
    Hannah Xiong


  2. Hian Rodrigo 1 Reputation point
    2021-07-21T13:55:30.433+00:00

    Hi, I create this GPO, but the users lost access to documents and desktop for example. I want to know if there is a way that the users can have access to C: ( but can't save or create files and folders) But also can continue to use the users normally(all users folders).


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.