Setting up GPO to assign file system permissions

  • Thread starter Thread starter arameth
  • Start date Start date
A

arameth

I am trying to set up a policy that will assign file
permissions on a specific file (explorer.exe), in order
to restrict access to it across all of our Citrix
Metaframe servers.

To do this, I opened the default domain policy in the
Group Policy editor. I went to 'computer
configuration', 'security settings', and 'File System'. I
added the file 'c:\winnt\explorer.exe', configure deny
execute permissions for the user group I wanted to
restrict, deselected the option for the file to allow
inheritable permissions to propagate.

However, whenever I log in to the servers, no matter
which user I log in with (domain admin, regular user),
the permissions remain unchanged (everyone,fullcontrol).

Anyone out there have experience pushing NFTS permssions
via GPO's before, that can give me some direction?
 
Back
Top