

If there have been no issues so far, then that is fine, *IF* it is actually working.Ĭertain areas require write allowances, as many programs rely on them for log files and will throw up errors without them. System files are always locked down for non-administrative users by default. Most of these programs will set permissions on log files/folders and the such when created. If they can write to the C drive something is not configured correctly in your GPO.Ĭertain areas require write allowances, as many programs rely on them for log files and will throw up errors without them. If you have locked down WRITE access to the C drive the users being able to READ from the C drive is completely safe. How does the software monitoring them allow them to install software? I would recommend replacing that software right away if it does!Agreed - this doesn't seem even close to right. How can merely being able to access C: allow them to assign themselves local admin rights? There plenty of resources out there for people to start causing issues. to make things worse we have s/w that monitors student pc's which in turn allows them access to install s/w using.

If users can access c: then they can assign themselves local admin rights.

I have locked down c: via gpo in addition to hiding the system drives.If I open explorer I can't access system drive and I only have my mapped drives.
