Prevent desktop icons from being created

Hello all!
Does anyone know of a way to prevent users from creating new icons on the desktop? We do not want to use the "hide all icons on the desktop" option because we still allow them to use "My Computer" and "Internet Explorer", plus any ZEN pushed icons that we place on the dekstop after they login. We only want to prevent a normal non-localadmin user from creating new icons on the desktop.
Thanks!
Larry

Have you tried redirecting %DESKTOP% to a Read-Only share?
You could script the removal of NTFS rights to the DESKTOP folder in the
user's profile dir via ZEN as well.
"Larry Cupp" <[email protected]> wrote in message
news:mSN3f.2498$l%[email protected]..
> Hello all!
>
> Does anyone know of a way to prevent users from creating new icons on the
desktop? We do not want to use the "hide all icons on the desktop" option
because we still allow them to use "My Computer" and "Internet Explorer",
plus any ZEN pushed icons that we place on the dekstop after they login. We
only want to prevent a normal non-localadmin user from creating new icons on
the desktop.
>
> Thanks!
>
> Larry

Similar Messages

  • Prevent infotype 0416 from being created under certain conditions

    Hi,
    Based on an advanced leave formula I can determine at runtime whether or not the infotype 416 record should be created or not. The formula is working.
    What is not working is that I need to find a way to prevent the 416 record from being created when the formula returns certain values. I have looked at ZXPADU02 and various other user exits and badi's but to no avail. The ZXPADU02 does not have the field which needs to be checked i.e. PA04160-NUMBR.
    Regards,
    Warren.

    Hi,
    The data is in INNNN structure.
    Write this code in include ZXPADU02 & set a break-point & check the value.
    case innnn-infty.
      when '0416' .
    perform validate_it0416
            using innnn
                  ipsyst.
    FORM validate_it0416 USING    p_innnn
                                   p_ipsyst.
       DATA: i_psyst LIKE psyst.
       DATA: i_nnnn  LIKE prelp.
       DATA: ps0416 LIKE ps0416.
       i_psyst = p_ipsyst.
       i_nnnn  = p_innnn.
       ps0416  = i_nnnn-data1
    if ps0416-numbr = ' '  "<b> check ur ondition here</b> endif.
    Hope this helps & solve your problem.
    Thanks,
    Sarika.

  • Prevent resource fork from being created on windows network shares

    I've already seen this article on how to prevent creating ds_store files on windows machines:
    http://docs.info.apple.com/article.html?artnum=301711
    But I haven't seen any way (short of buying software) to prevent the resource forks from being created. OSX creates resource forks on remote network volumes that pile up, are useless to the windows users, and creates a lot of grief.
    For every file copied to a windows share, OSX is putting a duplicate (unopenable) file with an underscore prefix:
    _file1.psd
    _file2.psd
    file1.psd
    file2.psd
    This is kind of rude network behavior, and I'd like to stop doing it.
    Isn't there some sort of terminal command similar to the .ds_store solution I posted above?

    I swear I saw a hack for that somewhere, but give up after 3 hours of searching for it!
    Seems like BlueHarvest at $10 is the best solution as it is...
    http://www.zeroonetwenty.com/blueharvest/
    Wondering if we couldn't "invent" something to add to that com.apple.desktopservices.plist file!?

  • Prevent My Sites from being created

    This seems like it should be simple but I must be missing something. I am trying to disable MySites on my Farm. Currently my user profile sync is working. But if I create a new test user and
    add it to my site I click on his name and get the grey "User Information" screen. Then if I make a change to the AD object and run "Start Profile Synchronization" once the sync finishes I go back and click the user that I just added it
    tries to redirect me to their MySite Profile and prompts me for credentials. 
    I disabled Use Personal Features, Create Personal Site, and Use Social Features for everyone. 
    I also turned off “Self-Service Site Creation”
    If I delete the Profile from “Manage User Profiles” make a change in AD and run "Start Profile Synchronization" it then recreates the MySite Profile and prompts me for credentials.
    I have stopped and started the User Profile service thinking that changes were not applying but I am not sure what I am missing.
    Thanks
    -Eric

    Ok, so the userdisp.aspx page is from the "User Information List" which is a hidden list on a site collection.  This list is the ONLY profile someone has if they use SharePoint Foundation, as their is no user profile service.  However
    in SharePoint Server, you have the user profile service, which is used to populate this "User Information List"... there is a timer job that will run to synchronize what is in the profile vs what is in the user information list, and update the User
    Info List based on what is in the profile.  This timer job is somewhere around hourly...
    Some things you can do if this is not working right
    stsadm -o sync -listolddatabases <#of days to check if it has been synced for>
    and if you find that some are not being synced, you can clear this cache out by doing
    stsadm -o sync -deleteolddatabases <#of days>
      this basically cleans up the sync list so they can be re-added. 
    You can edit the list view of the User Information List, so that you get an edit button to show up, and then you can manually update the user info list, but I wouldn't recommend it, and it will likely get overwritten when this sync job runs.
    Oh - almost forgot... this user info list is different on every site collection, so if you have 1000 site collections, and a user or 2 that visits each one, that user will be listed in 1000 user info lists.

  • Prevent apps and icons from being rearranged or deleted?

    Is there a way to prevent apps and icons from being rearranged or deleted?
    My three year old son likes to move them around and delete them. I don't want to lock him out because he loves to play many of the learning apps and games.

    I use different screens for my apps. My 6yo son has his own page with folders for games, education, and books. That is the default page, in case for some reason he's the one to turn on the phone it goes straight to that. The next page is default apps. Can't harm them. Then I've got some test apps, that I haven't decided if I'll keep them. Then there's a few games my DH plays. The last page is mine, with those things I don't want my son messing with. He knows its there and he knows he can't mess with them.
    My son is older than yours, but if you aren't going to be watching him the entire time he's got your phone, that may be the best way to go. And make sure he knows what he can and can't do on the phone. If he can't understand that, he will probably need to be supervised the whole time. No locking features that I have found, and I've looked!
    Good luck!

  • .DS_Store files on USB thumbdrives - a way to stop them from being created?

    Hello!
    Forgive me if this has been asked to death, but at school I need to copy homework files back and forth to the school's XP-based computers constantly. Because in any given day I usually update half a dozen files across the "homework" folder on my Powerbook, it's easier just to copy the entire folder (and its subfolders) to my 2-GB, FAT-32 formatted flash drive each night - all 500 files (and 150 MB). Of course, this also leaves hundreds of .DS_Store and ._filename files to clutter "Windows explorer" windows.
    My question is how do I remove (and prevent creation of) these files selectively? I know that they are used by the finder to store thumbnails, spotlight comments, and labels. The big problem is that while I want to remove these files from the homework folder (and some other folders), I DO NOT want to remove them from a few other folders on the flash drive - which I use to make quick backups of files from my Mac.
    I know that I can prevent OS X from creating them altogether with certain utilities, and I know that I can get third-party utilities that allow me to remove these files from flash drive and/or prevent the creation of the files for entire volumes, but is there something I can do to remove them from only certain folders?
    Also, since I do not always know beforehand what directories I might make, I'd like to be able to create a "white list" of only certain directories (and their sub-directories)that won't be touched, while all others will have their ".DS_Store" and "._filename" files removed.
    Finally, because I'm often a hurry when I go to copy files, I'd rather not sit there and run terminal commands or a program every time I copy a folder over to the flash drive. Is there some way to prevent them from being created in these certain folders altogether, automatically? An applescript or terminal command that I can program to run from the script menu perhaps? I don't mind opening a program or script, I just don't want to have to sit there manually removing the files.
    Thanks,
    -Dan

    I had a similar problem awhile back and asked for help in the Applescript forum:
    http://discussions.apple.com/thread.jspa?threadID=954738&tstart=0
    Unfortunately the revised jive software formatting function here in the forums has totally messed up things like posted scripts. What you'll see in the scripts discussed is no longer what was there originally. I just now put a copy of the script I'm using up in zip format here:
    http://homepage.mac.com/francines/.Public/CopyStrip2Fat.zip
    Unzip and open in Script Editor to get some idea of what it is really supposed to be. The idiot formatting of the revised jive software has replaced some things with a carriage return, a semi-colon, and close quote, thus rendering some lines meaningless.
    To see the source of the script I quoted, see this MacOSXHints thread:
    http://www.macosxhints.com/article.php?story=20040726164957299
    The script is in the comment by cougar718. You might take a look at other comments as well.
    Francine
    Francine
    Schwieder

  • Preventing expired batch from being sold

    Currently in one of our client's setup, I can select expired batch from the list of items. Is there a way to prevent expired items from being selected when creating sales order (VA01) or, if the user can select the expired item, at least display an error or warning message?

    Hi,
    Do try making the batch in resticted use in change batch basic data1 tab,activate radio button of batch status for Batch restr.
    It makes
    Batch in Restricted-Use Stock
    Specifies that the batch is included in restricted-use stock.
    Use
    If, though a batch has the status "restricted", you want to use a goods movement to post a quantity to unrestricted-use stock, the quantity is posted to restricted-use stock and not to unrestricted-use stock.
    If the status of a batch is set to restricted, the total unrestricted-use stock is transferred to restricted-use stock by means of a transfer posting. A material document is created.
    You cannot change the status of a batch (unrestricted/restricted) in a goods movement, only with the following functions:
    by maintaining the batch master record manually
    using the control function provided in the QM system
    Configurations for Restricted-Use Stock
    For planning purposes, restricted-use stock is treated like blocked stock, that is, it is either available or not available, depending on your system configuration.
    Withdrawals from restricted-use stock are either possible or not possible, depending on your system configuration.
    The status of a batch can be considered in batch determination, that is, you can search for unrestricted or for restricted batches.
    _(This has been adopted from SAP documentation.)
    Change batch T.code-*MSC2n*Regards,
    Reddyy

  • Office 365 AAD Password Writeback not working; Event Viewer Error: 0x80230619 (A restriction prevents the password from being changed to the current one specified.)

    Hello all,
    I'm currently setting up a Proof Of Concept setup with directory synchronisation and password syncing to Office 365, leveraging AAD Premium for the password reset and password writeback to on premises
    AD functionality. Directory Sync + Password Sync is working flawlessly with the AADSync tool. However, upon requesting a password reset for a user, I'm hitting a password writeback error. The webpage states that the password does not meet the password
    complexity policy, while it does. I can set that particular password for that account at the on premises AD without any problem.
    In the event viewer at the AADSync server, I'm seeing this Error pop up whenever I try to reset the password:
    An unexpected error has occurred during a password set operation.  "BAIL: MMS(4032): ..\server.cpp(11003): 0x80230619 (A restriction prevents the password from being changed
    to the current one specified.) Azure AD Sync 1.0.0475.1202"
    My Setup:
    Windows Server 2012 AD with a single forest
    Seperate domain joined Windows Server 2012 for AADSync tool
    AADSync version 1.0.0475.1202 with options password sync, password writeback enabled
    Service account for AADSync tool with Replicating Directory Changes and Replicating Directory Changes All permissions
    on root AD forest structure with inheritance to all objects. This account also has the permissions to Change Password and Reset Password on all descendant
    User Objects.
    AAD Premium for my office 365 tenant
    AAD Premium licenses for the test users and the office 365 account used to sync to Office 365. This account is also Global Admin.
    Could anyone help me with this? Is there something I’m missing here? My guess is that the AAD is not trusted or the service account for AADSync tool does not have the proper permissions. I’ve tried
    many options, like setting the AADSync Service account to Enterprise Admin or granting the service account Full Control over that particular user.

    Concerning my issue:
    The Default Group Policy setting: Minimum Password Age is set at 1 day. As I was testing this feature with new users, their provisioned passwords were less than 24 hours old and the Minimum Password Age of 1 prevented the change of the password.
    After changing this to 0 days in the Default Group Policy, my password resets started working for newly created users. While this might not have affected existing users in production, it had me looking and searching for permission issues on my AD.
    So for those that might be experiencing ADSync Event ID 6329 and PasswordResetService Event ID 33008 Errors when trying to do a Password Reset using AAD Premium with Password Writeback, it might be helpful to check the applied password policy.
    The issue is solved.

  • How do I create a desktop Icon for Adobe create pdf?

    How do I create a desktop icon for Adobe create pdf?

    Hi, ken.
    You can access ExportPDF from your computer more quickly in three ways:
    You can download and install the CreatePDF Desktop Application. More info is here. With this application, you can drag PDF files onto a desktop icon and have those converted to Office files. (If you subscribe to the CreatePDF service, this application will also allow you to create PDF files.)
    You can download and install the newest Adobe Reader and access the service using Reader's Tools Pane on right. Then, any time you have PDF open in Reader, you can (with a couple of clicks) convert that PDF to an Office file.
    You can drag the webpage icon from your browser to your desktop. This will create a shortcut to the ExportPDF website on your desktop. Here are some instructions for doing that using Internet Explorer or Firefox.
    Let us know if you have additional questions or issues.
    Dave

  • Stop Inbound IDOC's from being created

    I want to stop inbound IDOC's for a particular partner (type LS) from being created in our R/3 system. Is there a way to do this? I am aware these can be stopped in the middleware, but this is not possible in our case.  I am also aware that I can stop these IDOC's from being processed via the partner profile, however, there will be a huge number of useless IDOC's that will be created in our system and I want to avoid that.
    Hence, I do not want the inbound IDOC's to be created in the first place even though they are transmitted to SAP. Is this possible?
    Any inputs will be highly appreciated.
    Thanks,
    Raghu.

    Hi Satwik,
    Choose Idoc in WE02.
    Get port name, Then in WE21 get RFC name.
    Go to transaction SMQS - Here we can block this RFC instead of blocking the queue.
    Thanks,
    Anil

  • How to lockdown and prevent add-ons from being installed?

    Hi. I'd like to lockdown an installation of Firefox on a Win XP computer, to prevent add-ons from being installed by limited account users. How do I accomplish this please?

    Use a mozilla.cfg file in the Firefox program folder to lock prefs or specify default values.
    Place a file local-settings.js in the defaults\pref folder where you also find the file channel-prefs.js to specify using mozilla.cfg.
    pref("general.config.filename", "mozilla.cfg");
    pref("general.config.obscure_value", 0); // use this to disable the byte-shift
    See:
    * http://kb.mozillazine.org/Locking_preferences
    You can use these functions in mozilla.cfg:
    defaultPref(); // set new default value
    pref(); // set pref, but allow changes in current session
    lockPref(); // lock pref, disallow changes
    lockPref("xpinstall.enabled", false);

  • How to stop volume icon from being displayed randomly

    How to stop volume icon from being displayed randomly

    Thanks for the quick response.
    I have a number of slides which act as a training module. The quiz follows this. All the answers to the quiz are in the module slides. I'd like the user to be able to see which questions they're failing on, but not be shown the answers, as, if they are failing the quiz, the whole module needs to be reviewed and the test retaken.
    If this isn't possible, I'll probably just remove the review option, thereby meaning my retake button can stay, and the user can just go back and re-read the module slides to learn the answers.
    Thanks

  • [svn:osmf:] 9861: Fixing bug where sizing pixel from the previous run of updateIntrinsicDimensions would prevent the dimensions from being decreased .

    Revision: 9861
    Author:   [email protected]
    Date:     2009-08-31 23:08:03 -0700 (Mon, 31 Aug 2009)
    Log Message:
    Fixing bug where sizing pixel from the previous run of updateIntrinsicDimensions would prevent the dimensions from being decreased.
    Modified Paths:
        osmf/trunk/framework/MediaFramework/org/openvideoplayer/layout/LayoutContextSprite.as

  • Prevent OST file from being excluded from workstation backups

    Is there a way to prevent OST files from being excluded from client/workstation backups in WS2012E?
    Thanks,
    Reg
    This is especially a problem for clients that have migrated to Office 365 exchange service as they have no local backup of emails that were deleted and think synced with Office 365.
    Reginald Hook

    OST files are not a local backup, they are a cache of what is in the mailbox.
    https://support.office.com/en-gb/article/Introduction-to-Outlook-Data-Files-pst-and-ost-6d4197ec-1304-4b81-a17d-66d4eef30b78#__toc290027730
    Robert Pearman SBS MVP
    itauthority.co.uk |
    Title(Required)
    Facebook |
    Twitter |
    Linked in |
    Google+

  • Is there anyway to set a passcode for my iPhone/iPad, but prevent the device from being disabled?

    My wife and I have iPhones, and also have an iPad. We also have three children, and recently they have been trying to guess our passcodes so that they can watch videos and play games. Trouble is, after 10 attempts, the device will disable for 60 seconds, and then if the 11th attempt is wrong, the device will disable for 5 minutes, etc. My iPad is currently disabled for 60-minutes. Grrr.
    Is there anyway to set a passcode to keep the children out, and yet prevent the device from being disabled on successive attempts? I realise that this feature is there to protect our devices from brute-force attacks, but we are being penalised, in that our devices become disabled for a period of time.

    Well, so you have to ask: Is the problem your iPad or your children? Another question: If they're not to watch videos or play games, then why are they on the iPad in the first place?
    Obviously you already know the answer to your question; there is no way to set it up the way that you want to. If you nonetheless feel that you should be able to do that, then put together your best case for it and make your wishes known directly to apple via their established Feedback links:
    http://www.apple.com/feedback/ipad.html
    Posting here is no substitute for doing that

Maybe you are looking for