domain user cannot delete file from desktop RRS feed

  • Question

  • Dear All

    Now my company have 1 domain server + 50 client PC include desktop and laptop. server running WIN2k3 R2 and client is running on WINXP + WIN2000

    My question is How do i set the GPO to (do not allow my end user delete any file from desktop or laptop)* user only allow to create, modify, Read.

    Thank all

    Tuesday, January 19, 2010 2:16 AM


  • First of all you need to NOT give them admin access to their computers.... Then the default permission of the file system should pretty much be locked down for them... remember they do need to write to some folder like their profile/temp folders...

    Otherwise you can control the permission on the files and folder by going to Workstations > Computer Configuration > Policies > Windows Settings > Security Settings > File System

    Alan Burchill http://www.grouppolicy.biz
    • Proposed as answer by Alan Burchill Tuesday, January 19, 2010 5:51 AM
    • Marked as answer by Wilson Jia Wednesday, January 20, 2010 2:25 AM
    Tuesday, January 19, 2010 5:51 AM