OneDrive and Drive Restriction Policy

Lindstrom, Dexter 1 Reputation point
2021-08-16T18:21:36.447+00:00

I have a Citrix Server environment where we hide and restrict the local drives on the servers. This has worked splendidly for many years. Recently, I started testing FSLogix to use for profile management. The goal with FSLogix is to address the limitations of a user OST file, Teams desktop client and OneDrive.

All was going pretty good (aside from the gigantic profile sizes) for Exchange Cached Mode and the Teams client. I hit a giant roadblock with OneDrive. OneDrive sets up a folder in C:\Users\NTID\OneDrive. These folders are restricted due to my GPO. The only way I found to get OneDrive working is to remove the drive restriction policy.

This leaves the C: drive wide open. By default the local Users group has read/write permissions all over the local drive. I dread the idea of manipulating the default OS ACLs all over the C: drive in order to get OneDrive working.

I have seen many references to some users simply removing the RUN option for users. However, there are many, many ways to still see and interact with the local files and folders outside of the RUN option. This is not an option for me.

Does anyone have a good solution for tight control of the local drives while still allowing access to OneDrive?

Windows
Windows
A family of Microsoft operating systems that run across personal computers, tablets, laptops, phones, internet of things devices, self-contained mixed reality headsets, large collaboration screens, and other devices.
5,479 questions
FSLogix
FSLogix
A set of solutions that enhance, enable, and simplify non-persistent Windows computing environments and may also be used to create more portable computing sessions when using physical devices.
495 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Lindstrom, Dexter 1 Reputation point
    2021-08-17T20:54:06.893+00:00

    Well the issue is not specifically tied to any one of the 3 items: GPO drive restriction policy, OneDrive client and FSLogix. The issue is the intersection of the 3 items.

    It would be great if OneDrive was more friendly with RDS, Citrix and other non-persistent environments. I imagine there are others trying to solve the same problem and allow OneDrive functionality while maintaining tight control of the local drives. Maybe most people just surrender the security of the C: drive to allow OneDrive functionality. I am hoping that some really thoughtful and creative individual has found a solution to maintain C: drive access while allowing OneDrive access.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.