G
Guest
I have a rather interesting issue regarding the Drive Redirection feature and
Group Policy...
Here's the setup:
Client on PC at Company A connects to 2003 Terminal Server at company B
Company A has drive Group Policy enforcing "hide these drives..." as well as
"prevent access to these drives.." set for C (blocks the user from accessing
the C drive on his local PC).
If the client turns on Drive Redirection, he has full access to "C on
(clientPC)" when he logs into the 2003 Terminal Server at Company B.
I've tried manually removing the C mapping through a script, but the drive
redirection feature keeps remapping this drive whenever the user tries to
access it. It appears that the Remote Desktop client is ignoring the client
PC's Group Policy settings and is mapping the drive anyways. The client has
full access to his C drive through Terminal Services drive redirection.
Has anyone else had to deal with this sort of issue? It's a pretty big
security hole since if it's ignoring Group Policy.
The only theory I have is that MS has enforce this restricted access
through Explorer.exe (much like their 'prevent program execution' setting)
instead of deeper in the OS. If this is the case then Remote Desktop may be
bypassing it which makes me wonder what else it could get past...
Any suggestions are welcome.
Group Policy...
Here's the setup:
Client on PC at Company A connects to 2003 Terminal Server at company B
Company A has drive Group Policy enforcing "hide these drives..." as well as
"prevent access to these drives.." set for C (blocks the user from accessing
the C drive on his local PC).
If the client turns on Drive Redirection, he has full access to "C on
(clientPC)" when he logs into the 2003 Terminal Server at Company B.
I've tried manually removing the C mapping through a script, but the drive
redirection feature keeps remapping this drive whenever the user tries to
access it. It appears that the Remote Desktop client is ignoring the client
PC's Group Policy settings and is mapping the drive anyways. The client has
full access to his C drive through Terminal Services drive redirection.
Has anyone else had to deal with this sort of issue? It's a pretty big
security hole since if it's ignoring Group Policy.
The only theory I have is that MS has enforce this restricted access
through Explorer.exe (much like their 'prevent program execution' setting)
instead of deeper in the OS. If this is the case then Remote Desktop may be
bypassing it which makes me wonder what else it could get past...
Any suggestions are welcome.