So okay… despite what seem like rational OUs, security groups, user permissions, etc and so forth, anyone can rightclick on the Start button and wander through other users’ profiles..?
Yes, i have already implemented a GPO to disable the context menu for start/taskbar/clock, but this seems clumsy and imprecise. Why does this silly rightclick override the permissions present in AD for the groups that are set up?
Is there any way i’m missing that enforces these permissions (or more importantly, the lack of them) when users access that ridiculous menu? Or is disabling the menu the only way? And lastly, is hiding the ability to get that menu simply obscuring or adding a few steps towards that security hole…?
yeeesh,
Rob