Shared WVD Environment

%3CLINGO-SUB%20id%3D%22lingo-sub-1455412%22%20slang%3D%22en-US%22%3EShared%20WVD%20Environment%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1455412%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20All%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EJust%20lab%20testing%20WVD%20environment%20to%20match%20our%20current%20RDS%20Farms%20environment.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWe%20run%20a%20shared%20RDS%20Farms%20servers%20where%20multiple%20clients%20connect%20up%20to%20our%20RDS%20Servers.%20We%20lock%20down%20the%20RDS%20servers%20using%20group%20policy%20so%20that%20they%20don't%20get%20to%20see%20each%20other%20on%20the%20servers.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWith%20WVD%20%2B%20FSLogix%20Profile%20Containers%20-%20I%20wonder%20how%20we%20can%20lock%20down%20C%3A%5CUsers%20folders%20so%20that%20one%20user%20cannot%20see%20another%20users%20folders%20in%20there%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20have%20tried%20restricting%20access%20to%20C%20Drive%20-%20but%20given%20that%20FSLogix%20container%20mounts%20in%20C%3A%5CUsers%20-%20the%20test%20users%20weren't%20able%20to%20access%20their%20documents%2C%20downloads%20etc%20folders.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWould%20be%20really%20good%20if%20someone%20has%20a%20way%20to%20achieve%20this%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1460273%22%20slang%3D%22en-US%22%3ERe%3A%20Shared%20WVD%20Environment%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1460273%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F694817%22%20target%3D%22_blank%22%3E%40limaecho%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI've%20found%20that%20most%20our%20on-prem%20RDS%20GPOs%20can%20apply%20to%20the%20pools%20host%2C%20you%20may%20just%20be%20able%20to%20publish%20similar%20GPOs%20to%20these%20new%20pool%20hosts.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThe%20storage%20location%20of%20the%20fslogix%20vhds%20will%20be%20locked%20down%20via%20these%20permissions%20so%20users%20cannot%20see%20or%20access%20other%20user%20folders%3A%3CBR%20%2F%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Ffslogix%2Ffslogix-storage-config-ht%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Ffslogix%2Ffslogix-storage-config-ht%3C%2FA%3E%3CBR%20%2F%3E%3CBR%20%2F%3EAre%20you%20wanting%20to%20restrict%20them%20from%20accessing%20C%3A%5CUsers%20so%20they%20do%20not%20see%20usernames%20of%20others%3F%20Similar%20folder%20permissions%20above%20applied%20to%20the%20pool%20host%20may%20allow%20access%20to%20C%3A%5CUsers%20and%20limit%20to%20only%20visibility%5Caccess%20to%20their%20user%20folders%20(username%20and%20local_username)%20but%20not%20others.%20Not%20sure%20though%20as%20the%20C%3A%5CUsers%20folders%20are%20removed%20with%20the%20session%20ends.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EOn%20the%20pool%20host%20I%20would%20imagine%20you%20do%20not%20have%20them%20as%20admins.%20They%20may%20be%20able%20to%20access%20the%20C%3A%5CUsers%20directory%20but%20they%20will%20not%20be%20able%20to%20access%20those%20folders.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1463101%22%20slang%3D%22en-US%22%3ERe%3A%20Shared%20WVD%20Environment%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1463101%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F666497%22%20target%3D%22_blank%22%3E%40CMurphyUSA%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThank%20you.%20Users%20can%20still%20%22see%22%20other%20users%20folders%20under%20C%3A%5CUsers%20-%20permissions%20just%20prevent%20access%20to%20getting%20into%20the%20folders.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20have%20semi-solved%20the%20issue%20now%20by%20restricting%20access%20to%20C%3A%20Drive%20and%20setting%20up%20hub%20mode%20for%20file%20explorer.%20This%20still%20shows%20the%20user%20his%20profile%20folders%20and%20prevents%20access%20to%20C%3A%20drive%20completely.%20The%20issue%20is%20when%20you%20use%20an%20application%20that%20allows%20open%20location%20(i.e.%20in%20outlook%20data%20file)%20-%20the%20C%3A%5C%20does%20open%20up%20and%20a%20user%20can%20get%20to%20C%3A%5CUsers%20and%20see%20other%20users%20folders%20in%20there.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1463717%22%20slang%3D%22en-US%22%3ERe%3A%20Shared%20WVD%20Environment%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1463717%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F694817%22%20target%3D%22_blank%22%3E%40limaecho%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20believe%20all%20you%20can%20do%20is%20restrict%20visibility%20by%2C%20say%20hiding%20the%20C%3A%5C%20drive%20from%20file%20explorer%20via%20registry%20or%20GPO%20(Amazon%20Workspaces%20does%20this%20be%20default%20for%20example).%20A%20user%20is%20going%20to%20have%20to%20be%20granted%20permission%20to%20the%20C%3A%5C%20and%20C%3A%5CUsers%20directory%20in%20order%20to%20do%20their%20work%20on%20any%20Windows%20PC.%20Third%20party%20file%20explorers%2C%20they%20will%20be%20able%20to%20view%20C%3A%5C.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ESounds%20like%20you%20just%20need%20to%20confirm%20the%20folder%20and%20sub-folder%20permissions%20on%20the%20C%3A%5CUsers%20directory.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThere%20is%20a%20GPO%20under%20User%20Config%20%26gt%3B%20Admin%20Templates%20%26gt%3B%20Windows%20Comp%20%26gt%3B%20Windows%20Expl%20%26gt%3B%20'Prevent%20Access%20to%20Drives'.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHopefully%20this%20is%20somewhat%20helpful%2C%20but%20I%20may%20be%20misunderstanding%20the%20need.%3C%2FP%3E%3C%2FLINGO-BODY%3E
Occasional Contributor

Hi All

 

Just lab testing WVD environment to match our current RDS Farms environment.

 

We run a shared RDS Farms servers where multiple clients connect up to our RDS Servers. We lock down the RDS servers using group policy so that they don't get to see each other on the servers.

 

With WVD + FSLogix Profile Containers - I wonder how we can lock down C:\Users folders so that one user cannot see another users folders in there?

 

I have tried restricting access to C Drive - but given that FSLogix container mounts in C:\Users - the test users weren't able to access their documents, downloads etc folders.

 

Would be really good if someone has a way to achieve this?

3 Replies

@limaecho 

 

I've found that most our on-prem RDS GPOs can apply to the pools host, you may just be able to publish similar GPOs to these new pool hosts.

 

The storage location of the fslogix vhds will be locked down via these permissions so users cannot see or access other user folders:
https://docs.microsoft.com/en-us/fslogix/fslogix-storage-config-ht

Are you wanting to restrict them from accessing C:\Users so they do not see usernames of others? Similar folder permissions above applied to the pool host may allow access to C:\Users and limit to only visibility\access to their user folders (username and local_username) but not others. Not sure though as the C:\Users folders are removed with the session ends.

 

On the pool host I would imagine you do not have them as admins. They may be able to access the C:\Users directory but they will not be able to access those folders.

@CMurphyUSA 

 

Thank you. Users can still "see" other users folders under C:\Users - permissions just prevent access to getting into the folders.

 

I have semi-solved the issue now by restricting access to C: Drive and setting up hub mode for file explorer. This still shows the user his profile folders and prevents access to C: drive completely. The issue is when you use an application that allows open location (i.e. in outlook data file) - the C:\ does open up and a user can get to C:\Users and see other users folders in there.

@limaecho 

 

I believe all you can do is restrict visibility by, say hiding the C:\ drive from file explorer via registry or GPO (Amazon Workspaces does this be default for example). A user is going to have to be granted permission to the C:\ and C:\Users directory in order to do their work on any Windows PC. Third party file explorers, they will be able to view C:\.

 

Sounds like you just need to confirm the folder and sub-folder permissions on the C:\Users directory.

 

There is a GPO under User Config > Admin Templates > Windows Comp > Windows Expl > 'Prevent Access to Drives'.

 

Hopefully this is somewhat helpful, but I may be misunderstanding the need.