Windows服务器 2016 GPO File System Security: Restricting Write Access to Root of Drive C:\. By default domain, users have rights to write in the root of Drive C:\, with this GPO we remove this ability.
1. 开始 小组政策管理 console;
2. Choose the GPO object, 右鼠标按钮单击, 然后单击 编辑;
3. 导航至 Computer Configuration\Policies\Windows Settings\Security Settings;
4. 鼠标右键 点击 File System 然后单击 Add File;
5. Select Local Disk (c:) 然后单击 好的;
6. In the Database Security window, set the permissions you want, then click好的;
7. In the Add Object window, select the ACL inheritance you want, then click好的;
8. The Group Policy Editor displays the new object name;