Restrict user from saving on their Desktop, My Documents, My Music, My Videos, My Pictures etc. via GPO

group-policywindows 7windows-server-2008-r2windows-vistawindows-xp

I want to accomplish the following task: A user must not have rights to save on their Desktop, My Documents, My Music, My Videos, My Pictures, etc.

I have already prevented and hidden all drives via GPO. However, user are still able to store files in the locations listed above.

Server OS: Windows Server 2008 R2

Client OS: Windows XP, Windows Vista and Windows 7

Best Answer

It's very easy if you are using Windows Server 2008.

  1. Create a Group Policy Object, go to Computer Configuration > Policy > Windows Settings > Security Settings > File System
  2. Right click and add %userprofile%\Desktop ....etc for the different folders that you want to restrict access to.
  3. Specify the rights for the specified folder(s) for users or user groups.