Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations SkipVought on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

How do I stop users from seeing the C: drive of my Citrix Server

Status
Not open for further replies.

mickgb

IS-IT--Management
Nov 6, 2003
8
0
0
GB
I have a problem with clients saving files to the C:\ drive of my Citrix Server - they sometimes forget that it is not their hard drive - does anyone know how I can prevent clients from seeing the C:\ drive from within applications eg. word, excel, windows explorer etc....

thank you
 
Thats a tricky one.

You can restrict access to local drives using Group Policy but unfortunately these settings are applied under the user branch rather than the machine branch so it will affect users managed by the GPO whichever machine they log into. Personally I don't allow my users access to their C: drives anyway, so possibly this would be something consider.

The setting to apply for this is \User Configuration\Administrative Templates\Windows Components\Windows Explorer\Hide these specified drives in My Computer – set to enabled then select drives affected by the policy.

When you say that they're writing to the server's C: drive, do you mean that they're writing to the My Docs folder etc. or other areas? If they're writing to the other areas on the folder then you should really look at the NTFS permissions to make sure they can't - limited users don't need write access to either the root of the volume of Program Files, WINNT etc. etc.

If you want to stop them from writing to the My Docs folder etc. and you have suitable file servers they use already you can redirect user's My Documents folder and others to a network share using Group Policy so they will always be writing to the same location no matter where they login.

Just some ideas, hope they are helpful :)
 
We have restricted access to the server's C drives (ie they can't see it when they browse windows explorer), but you can still access it if you type in C:\ and then enter in windows explorer.
 
There's a more restrictive GPO setting - deny access to specified drives - if you want to deny access completely.
 
Would that have any affect on the applictions that are running on the server ie if we deny full access to the C drive on the citrix server that is?
 
erm....well thats the question I had, which is why I didn't use that setting - it does sound a little extreme and the hide setting works well enough for me.

Looking at it logically I don't think it would - I think for example it is used if you allow users access to the command prompt etc. whereby they could still access the C: drive from there - my users aren't allowed access to the Run command, command prompt etc. so its not an issue, they are also limited to what they can do from Windows Explorer etc. so as I said the hide setting works OK for me.

Since the setting is under the user node anyway, it would be quite easy just to create a new OU with a new GPO with this setting enabled and drop a test user in there to see what happens - this won't affect the rest of the users at all - maybe I'll do this sometime!
 
The way Primate described it is exactly the way I'm doing it. I just disabled access to the drives through the group policy. I've been using this for almost a year and haven't had any issues.
 
Sure your not using 'hide these specified drives' instead of preventing access ? surely preventing access is gonna mess things up just a little to say the least

Andy
 
I'm 100% positive I have Prevent access to drives from my computer enabled. I also have hide these specified drives as well enabled not that it needs to be. No problems and I have lots of applications published.
 
Hi,

You could always try to use Local Policy Editor on each Citrix server, hide and prevent access to the drives.

However, the downside to this is that you do it for ALL users including Admins. If you have your boxes fully configured then this shouldn't be too much of an issue. You could always turn the prevention off if you need to do some Admin work!

Cheers,
Carl.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top