Re: c$

From: Steven L Umbach (n9rou_at_nospam-comcast.net)
Date: 06/09/05


Date: Thu, 9 Jun 2005 11:22:15 -0500

The C$ is available only for a user that is a local administrator on the
computer and can come in quite useful. The administrative shares can be
safely disabled on most computers [not domain controllers] or you can
disable file and print sharing or the server service on computers that you
have not need to offer any shares or be managed remotely via Computer
Management and other tools that use SMB. The server service can be easily
disabled via Group Policy. The best solution may be to modify the user
rights for access this computer from the network to include only the
users/groups that you want to be able to access any shares on a computer. If
for instance your domain users are members of the local administrators group
on domain computers and you are having problems with some users accessing
other domain computers via the C$ share you could put those computers into
an OU and configure a Group Policy linked to that OU so that the user right
for access this computer from the network contains only domain admins. The
link below shows how to do a registry change to disable administrative
shares if that is what you want to do but be sure to read the other
pertinent info. You could implement such a change with a Group Policy
"startup" script. --- Steve

http://www.petri.co.il/disable_administrative_shares.htm

"ANAS" <ANAS@discussions.microsoft.com> wrote in message
news:4B1723B2-7D9D-4C71-B79C-32D9578432ED@microsoft.com...
> hi,
> dear can u help how to disable the C$ i know the C$ is a default sharing,i
> need how to disable it to apply all the user in the domain by use such as
> group policy or another way.
> Thanks in advance.



Relevant Pages

  • Group Policy and restricting local administrators
    ... I am currently working on developing a group policy on a AD container ... I certain users to have virtually local administrator ... access to a series of servers, but there are a few things I do not want ... users inside of a container from be able to access the User Management ...
    (microsoft.public.windows.server.general)
  • Re: Preventing Users from removing their PC from the Domain
    ... Steven L Umbach wrote: ... purpose and understand that Restricted Groups can remove all existing ... simply be removing the Restricted Group, Group Policy setting. ... you are logged on as a local administrator. ...
    (microsoft.public.win2000.security)
  • Re: autosharewks changes to 0 due to gpupdate
    ... So wait, you have a group policy disabling the admin shares, you manually ... reset the shares on the workstations, and then the computers rehonor the ...
    (microsoft.public.win2000.registry)
  • Re: User Desktop ?
    ... Does it happen to a local user that is not a local administrator? ... it does not that would indicate a user configuration Group Policy setting ... and you can run rsop.msc on the domain computer to see what Group Policy ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Prevent users from changing domain name
    ... XP Pro has the network configuration group that you can add users ... Many users do not know what they can do as a local administrator while ... Use Group Policy to remove properties from the My Computer context menu. ... This is done in user configuration/administrative templates/desktop. ...
    (microsoft.public.win2000.group_policy)