Win2008 group policy headache

kohl

Limp Gawd
Joined
Apr 5, 2004
Messages
290
Greetings!

I am working on a project which involves setting up Terminal Services (windows server 2008) access to users in our organization. Part of this project involved locking down the desktop to restrict access, for example, only to mapped network drives.

One issue we immediately ran into is the windows explorer search bar in Windows 2008. Through testing, we have discovered that through this search, it is possible to gain access to local drives (C, etc) which have been removed from access with group policies.

After doing some searching online I have not come across much and am just shocked that this search isn't able to be removed or hardened in some way. I've published screenshots at the following URL which detail the issue we are running in to:
http://numinous.servegame.org/gp.htm

Has anyone seen this behavior before? I am having a hard time imagining that Microsoft intended the search function to allow such easy bypass of the hide and restrict group policies :confused::eek:

PS - this is the search bar from within Windows Explorer; not the search function from Start menu, etc.
 
there are 2 methods of keeping users out of drives via GPO, you can hide them (sounds like you've used this way) or you can deny access to them, (which may work, but obviously it'll need through testing in your environment).

edit: and don't forget, if you are not redirecting the start menu, to check for the old triple click on programs to see if it opens the folder, as they can navigate that way to get around the hdd of the machine they are on.
 
Back
Top