Windows Server 2016 GPO File System Security: Restricting Write Access to Root of Drive C:\. By default domain, users have rights to write in the root of Drive C:\, with this GPO we remove this ability.
1. Inizio Gestione delle politiche di gruppo console;
2. Choose the GPO object, Pulsante destro del mouse Clicca, e fare clic Modificare;
3. Navigare a Computer Configuration\Policies\Windows Settings\Security Settings;
4. Pulsante mouse destro click on File System e fare clic Add File;
5. Selezionare Local Disk (C:) e fare clic OK;
6. Nel Database Security finestra, set the permissions you want, quindi fare clicOK;
7. Nel Add Object finestra, select the ACL inheritance you want, quindi fare clicOK;
8. The Group Policy Editor displays the new object name;