We have a lot of servers running Windows 2008 r2 (RDS/Citrix). We try our best to lock down remote desktop and published applications.
Recently, one of my colleague showed me how he could use 7-zip to browse our network (with a simple user account). Actually, this is something that i never though we could use to do (I rarely check "little" app like that and put all my effort on "more important apps" like Office Suite, SQL client, etc.).
After checking again, it appears that users connecting to their remote desktop can use 7-zip to browse the network and access files and folders on servers. Fortunately, they can't open files, remove or move them but still I want to find a way to disable this.
I didn't find many docs or manuals for this purpose and since I cannot disable this functionality with GPO (I wish we could keep 7-Zip and not user another apps) could anyone provide me with some help?