Restricting Desktop Customization with GPO on Windows Server 2022

Raffaele Leto 0 Reputation points
2025-01-23T13:47:21.7933333+00:00

I'm aiming to create a Group Policy Object (GPO) to make the local desktop read-only for all users. This means users should be able to view all icons on the desktop but not modify their arrangement, add new ones, or delete existing ones.

What is the most effective GPO configuration to achieve this? Which specific settings should I modify to completely block desktop customization while still allowing all icons to be visible?

Windows Server
Windows Server
A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.
13,627 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Daisy Zhou 28,646 Reputation points Microsoft Vendor
    2025-01-23T14:02:01.12+00:00

    Hello Raffaele Leto

    Thank you for posting in Q&A forum.

    You can try the method in the similar thread below.

    https://answers.microsoft.com/pt-br/windowserver/forum/all/impedir-salvamento-local-na-%C3%A1rea-de-trabalho/ef871e34-20dd-4430-ada9-84765553eb60

    Note: Deny everyone all permissions (except Read) on the desktop, so this user only can read his/her desktop.

    I hope the information above is helpful.

    If you have any questions or concerns, please feel free to let us know.

    Best Regards,

    Daisy Zhou

    ============================================

    If the Answer is helpful, please click "Accept Answer" and upvote it.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.