윈도우 서버 2016 GPO File System Security: Restricting Write Access to Root of Drive C:\. By default domain, users have rights to write in the root of Drive C:\, with this GPO we remove this ability.
1. Start 그룹 정책 관리 console;
2. Choose the GPO object, Right Mouse Button click, 그리고 클릭 편집하다;
3. 다음으로 이동 Computer Configuration\Policies\Windows Settings\Security Settings;
4. 마우스 오른쪽 버튼 click on File System 그리고 클릭 Add File;
5. Select Local Disk (C:) 그리고 클릭 좋아요;
6. In the Database Security window, set the permissions you want, then click좋아요;
7. In the Add Object window, select the ACL inheritance you want, then click좋아요;
8. The Group Policy Editor displays the new object name;