I have a problem keeping users from saving to the desktop. They are using a mandatory roaming profile on Metaframe XP, Server/AD 2003 to run published apps. I have a GPO set up to hide/prevent access to the local drives, which prevents users from saving anywhere on the M drive EXCEPT the Desktop and My Documents folders of their user profile. The only way I have figured out how to prevent people saving stuff there is to restrict the NTFS permissions on these folders to read-only. This works great without a roaming profile, but WITH the roaming profile, they get an error saying that the roaming profile failed to load. I can't find anything in the GPO to restrict saving to the desktop, only to hide the icons on the desktop. Has anyone run into this?
Andy
Andy