Hi shocko,
Based on my test, the scenerio is as you stated. We can access the profile via inputing c:\users\%username%and can creare and save new file. Although you Prevent access to drives from My Computer, users still have right to save files to their
user profiles.
The easy way to prevent users to save data on a location is set folder redirection policy, redirect users’ desktop to a network share where users don’t have write permission.
Create a network share on your server, but don’t grant write permission for domain users group.
Hope this helps!
Regards,
Lany Zhang