GPO: disable access to previous versions

Introduction

In this tutorial, I’ll explain how to disable access to previous versions by GPO from client computers. Although convenient, this feature in case of user error can do some damage.

As a reminder, in normal operation, access to previous versions is available by right-clicking on the folder.

Shadow copy

The GPO I am going to mount you will disable access to previous versions on the networks location.

GPO: Disabling Access to Previous Versions

1. From the Group Policy Management console, right-click on the OU 1 that contains the items and click Create GPO in this area, and link it here 2 .
New strategy

2. Name strategy 1 and click OK 2 .
Strategy name

3. Create the strategy, right click on 1 and click on Edit 2 .
Edit strategy

4. Go to Location: Computer Configuration / Administrative Template / File Explorer / Previous Version 1 . Open the Hide Previous Versions List for Remote Files 2 setting.
Parameters

5. Activate 1 the parameter then click on Apply 2 and OK 3 .
Parameters

This setting allows you to disable access to previous versions on the folder, this prevents users from doing the restores themselves. If you want to leave the users autonomous, it is advisable in this case to enable the Prevent the restoration of previous remote versions.

6. Summary of the strategy:
Resume

7. Result: The Previous Versions tab is no longer available.
Result

Conclusion

Limiting access to previous versions for users should be applied, by experience once the user sees the manipulation, he will attempt to reproduce it by himself when he needs a file restore, and a false manipulation with previous versions can either restore the data set to T moment, saturate the disk space of the share …

 

 



Related Posts


GPO: Enabling and Configuring WinRM – Remote Management

Table Of ContentsPresentationGPO for WinRMConfiguring WinRMService configuration Presentation In this tutorial, we will have how to enable and configure remote management (WinRM - Windows Remote Manag

GPO: Installing the FusionInventory Agent

Introduction Following the many messages I can see on the forum concerning the installation of the Agent FusionInventory, I will explain how I have been doing for several years. In this article, I'll

WSUS: Set up client-side targeting

Presentation The client-side targeting on WSUS, when enabled, allows you to directly assign to a group declare in the console. This declaration is not done GPO or by modifying the register of the cust

Scroll to Top