Windows-Server 2016 GPO File System Security: Restricting Write Access to Root of Drive C:\. By default domain, users have rights to write in the root of Drive C:\, with this GPO we remove this ability.
1. Start Gruppenrichtlinienverwaltung console;
2. Choose the GPO object, Right Mouse Button click, und klicken Bearbeiten;
3. Navigieren Sie zu Computer Configuration\Policies\Windows Settings\Security Settings;
4. Rechte Maustaste click on Dateisystem und klicken Add File;
5. Wählen Local Disk (C:) und klicken OK;
6. Im Database Security window, set the permissions you want, dann klickenOK;
7. Im Add Object window, select the ACL inheritance you want, dann klickenOK;
8. The Group Policy Editor displays the new object name;