Guide Create File System security GPO in Windows Server 2016. By default domain users have rights to write in root of Drive C:\, with this GPO we remove this ability.

1. Start Group Policy Management console;

2. Choose GPO object, Right Mouse Button click and click Edit;

3. Navigate to  Computer Configuration\Policies\Windows Settings\Security Settings;

4. Right Mouse Button click on File System and click Add File;

5. Select Local Disk (C:) and click OK;

6. In the Database Security window, set the permissions you want, then click OK;

7. In the Add Object window, select the ACL inheritance you want, then click OK;

8. The Group Policy Editor displays the new object name;