Edit files on Desktop PC in AD

Marzio Bersani 1 Reputation point
2020-08-04T06:41:27.567+00:00

On a PC that belongs to an Active Directory domain, I would like to prevent the ability to edit/add/delete files or folders on the desktop by using a domain-wide policy so that it applies to all non-administrators users in the domain.

Can it be done?

Thank you.

Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
6,149 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Leon Laude 85,716 Reputation points
    2020-08-04T07:11:36.35+00:00

    Hi,

    This should be possible with Group Policies, you can follow along here:
    Restrict user from saving on their Desktop, My Documents, My Music, My Videos, My Pictures etc. via GPO

    Group Policy Prevent Saving to Desktop

    Another way would be to use folder redirection to a network share:
    https://video2.skills-academy.com/en-us/windows-server/storage/folder-redirection/deploy-folder-redirection

    ----------

    (If the reply was helpful please don't forget to accept as answer, thank you)

    Best regards,
    Leon

    0 comments No comments