Recommended Posts

I work for a high school as a computer technician. Me and the other tech want to set a specific wallpaper that will display on all computers when an user is logged in. We plan on using a GPO to enforce this.

We tried using a registry setting to change the wallpaper at login. However, after they log in, they can still change it. We have display properties disabled, but the students found several programs that still let them change the wallpaper.

Is there any way to absolutely force the wallpaper, with no way whatsoever to change it? A GPO is majorly preferred, but if there is something we would have to edit on the individual computers (like a third party program or something that can't be set through GPO), that wouldn't be too much of an issue.

Link to comment
https://www.neowin.net/forum/topic/699048-forced-wallpaper-via-a-gpo/
Share on other sites

Did you set it in

GP>User Config>Admin template>desktop>active desktop> allow only bitmapped wallpaper /active desktop wallpaper

GP>User Config>Admin template>control panel>display> prevent chaging wallpaper

I -think- thats how I stoped my users I can't see my GP as I got made redundant but looking on my 2k3 server it looks right.. let me know

Did you set it in

GP>User Config>Admin template>desktop>active desktop> allow only bitmapped wallpaper /active desktop wallpaper

GP>User Config>Admin template>control panel>display> prevent chaging wallpaper

I -think- thats how I stoped my users I can't see my GP as I got made redundant but looking on my 2k3 server it looks right.. let me know

It seems that we already tried all of those. I checked every setting in our group policy and all of those were already enabled and applied to the computer labs.

They do work quite well, but it seems that people are still able to override them. Even Firefox, if you right click on an image on a webpage, you can still set it as the wallpaper, even with those policies applied.

We just tried this GPO on a single pc:

User Configuration> Administrative Templates> Desktop> Active Desktop> Active Desktop Wallpaper

We enabled that, and than changed the path to a local wallpaper. It worked, and anything we threw at it couldn't change the wallpaper. However, it was logged in as a local account.

We logged out of the local account, and into a domain account (a test account with student permissions). The wallpaper didn't even apply, and we were able to change it with ease using the third party programs and Firefox.

Tony (the other tech) than logged in as his non-administrator account, and the wallpaper did apply, and he again was unable to change it.

It probably is worth noting that every account has redirected folders and roaming profiles. The tech people (Tony and I) are the only exception to this rule (we use flash drives instead).

So long story short:

1) We used a GPO to save this setting

2) The accounts that do not have redirected folders or roaming profiles are effected by this GPO, and can't change wallpapers, but that would be pretty much me and one other person.

3) Everyone else (who does have redirection and roaming) is not effected by this GPO.

It seems that the issue is with the roaming profiles and folder redirection. Any ideas?

The issue is not that you use roaming profiles and folder redirection, the issue is that the domain account overrode the local account settings you made in the local GPO. Make a test OU in the AD and do your tests with that. Never test a domain policy with a local account, nor ever test a policy made locally with your domain account. A test OU costs you nothing, so make them and use them. Test accounts, too.

That is what I thought at first, I thought the domain's GPOs were overriding the local ones, but like I said, the other tech was able to log into his account (domain user, non-administrator, no roam or redirect) and the local GPO applied to him. So we did manage to get the local GPO to apply to a Domain user.

We essentially did try that, to the same results.

We did try using the GPO on a domain level, and applying it to the container that our test computers are in, and seemed to have even worse luck than a local policy. We could not get the wallpaper to apply to a single account

What would happen if you created a new computer OU. created a new user & applied a group policy to that OU does that work?

Ah! If I remember correctly I had to apply the GPO to the User & Computer. I don't know why but I'm sure it worked.

BTW Joey H: where on Earth are you?

We essentially did try that, to the same results.

We did try using the GPO on a domain level, and applying it to the container that our test computers are in, and seemed to have even worse luck than a local policy. We could not get the wallpaper to apply to a single account

You can't apply a User Configuration GP to a computer. That would be a very large mistake. You apply User Configs to user objects, and Computer Configs to computers.

u2_storm: I'm on the part that isn't an ocean. More specifically, St. Louis metro.

On Tuesday and Wednesday, I had a few problems I had to deal with (one of our servers was down, and we had to get a computer lab moved), so I didn't pay much attention to the wallpapers. I'm gonna try the new computer OU on Monday and hope it works. I'll let you all know. But I do appreciate all the help so far. Thank you :)

http://support.microsoft.com/kb/327998

Following the above instructions, they will not be able to change the wallpaper in IE but will be able to in Firefox. Even of they change it in Firefox, the wallpaper will reset back to gpo defined wallpaper after reboot or logoff/logon. I have the same problem at my job so I feel your pain :/

Edited by VRam

Or just leave it alone. what harm to work can a picture on a desktop do? They allow users to feel relaxed and will allow them to work in an environment that is familiar to them, increasing their productivity. Forcing a boring same wallpaper every login is silly and boring.

Or just leave it alone. what harm to work can a picture on a desktop do? They allow users to feel relaxed and will allow them to work in an environment that is familiar to them, increasing their productivity. Forcing a boring same wallpaper every login is silly and boring.

Its a distraction. Our kids should be focusing on their work and not searching the net for a the latest pic of 50 cent or the newest Ferrari to set as their wallpaper. People also tend to frown on their PC greeting them with a pornographic image when booted. I like keeping all the machines uniform and neat and since I'm the one who has to fix what they screw up, I feel I have a right to make it so.

Or just leave it alone. what harm to work can a picture on a desktop do? They allow users to feel relaxed and will allow them to work in an environment that is familiar to them, increasing their productivity. Forcing a boring same wallpaper every login is silly and boring.

Leaving it to the user could contravene the company's AUP. Don't spout crap about a work environment you don't understand.

Not sure why the wallpaper can be changed despite the group policies, but how about overriding the default permissions for the registry key (whatever it is) that defines the wallpaper currently in use? I would *think* that if a user doesn't have sufficient rights to update the key--whatever the means used--then a new wallpaper couldn't be specified...

I thought I found the magic bullet when someone on the net suggested unregistering the shimgvw.dll (removes the "set as desktop background" context menu, but found that also disables the Windows picture and Fax viewer which makes the trick useless. I guess you could install another picture viewer, but thats just another program to maintain. Microsoft should fix the group policy setting to do what it claims to do prevent changing wallpaper.

Or just leave it alone. what harm to work can a picture on a desktop do? They allow users to feel relaxed and will allow them to work in an environment that is familiar to them, increasing their productivity. Forcing a boring same wallpaper every login is silly and boring.

We have many complaints from teachers about wallpapers. There are some students who spend way too much time looking for new wallpapers and not paying attention to their classwork. Also, alot of students seem to have no sense of decency. I've seen wallpapers containing nudity, pornography/hentai, racism, sexism, drug use, just about everything that someone could find highly offensive. The teachers do send students out of class when something like this comes up, and the students do receive discipline, but we don't want it there in the first place. Even if it is not inappropriate, students like to show off their wallpapers, which creates distractions in class.

Not sure why the wallpaper can be changed despite the group policies, but how about overriding the default permissions for the registry key (whatever it is) that defines the wallpaper currently in use? I would *think* that if a user doesn't have sufficient rights to update the key--whatever the means used--then a new wallpaper couldn't be specified...

To my understanding, registry editing is pretty much restricted. The users can't directly access the registry, and the fields that they can edit are very limited in number. I would believe that the registry strings that control the wallpaper would be locked, but if they aren't, that could be a pretty big hole right there. That is defiantly something I will talk to the other tech about, and we'll investigate it.

Edited by Joey H
To my understanding, registry editing is pretty much restricted. The users can't directly access the registry, and the fields that they can edit are very limited in number. I would believe that the registry strings that control the wallpaper would be locked, but if they aren't, that could be a pretty big hole right there. That is defiantly something I will talk to the other tech about, and we'll investigate it.

I don't suspect that students are directly editing the registry, but whatever means they use to change the wallpaper, would run using the same security privileges as that user.

So if you remove the privileges for the registry key for UserX, then it doesn't matter *how* UserX tries to change the wallpaper (desktop properties, Use As Wallpaper in a browser, etc)--all those methods should fail because the process that attempts to write the new value is also running as UserX.

We did eventually manage to stop people from changing their wallpapers. It's a fairly crude method, but it does work well.

There were two ways people were changing wallpapers:

1) Mozilla Firefox

2) Third party wallpaper managers

I don't know exactly how, but the other tech managed to lock "firefox wallpaper.bmp", so that if someone tried to change their wallpaper in firefox, it would not change. I think he found a way to make the file read only, and so that people can't change the read-only status. I don't know how he pulled that off, I wasn't there that day.

The third party programs were easy. Students don't have permission to write any data to program files, they only have read only access. The same goes for the windows directory. So the easiest solution was to use a GPO to block all programs not located in C:\Program Files, C:\Windows, or specific read-only shares located on one of our file servers.

It's not the best solution, but so far it seems to be taking very good care of the wallpaper issues. Furthermore, students were installing games into their documents folder, and that took care of those games too.

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • First time clicking on a Sayan Sen article after he started making clickbait, vague headlines recently. Didn't read, just came here to say the headline doesn't look like very cheap, vague clickbait this time. Are you okay?
    • Good review, and yeah the benchmark breakdown is pretty clear but also a little messy in a good way. It’s kinda interesting to see where the RX 9070 GRE slides in between the 7800 XT and the 9070 XT , especially when it comes to AI tasks and Blender style workloads. The side by side with Nvidia’s RTX 5070 and 4070 makes it feel obvious just how competitive the mid range GPU scene has gotten lately, and that’s great for creators and gamers too since you can pick based on your priorities rather than only chasing one single thing.
    • That's it. I finally uninstalled Firefox because they often keep pushing buggy updates, only to test them later and make users suffer. No longer is it my alternative browser to Edge. What a waste of energy. Firefox is bad for the environment, just like Chrome (wasting RAM/energy).
    • Microsoft Weekly: new Surface, Windows 11 26H2, and more by Taras Buria This week's news recap is here, with Microsoft announcing Windows 11 version 26H2, launching new Surface devices powered by Snapdragon X2 processors, GTA VI preorder date and cover art, fresh Windows 11 preview builds, a quirky phone-sized e-reader with a physical dial, and more. Quick links: Windows 10 and 11 Windows Insider Program Updates are available Reviews are in Gaming news Great deals to check Windows 11 and Windows 10 Here, we talk about everything happening around Microsoft's latest operating system in the Stable channel and preview builds: new features, removed features, controversies, bugs, interesting findings, and more. And, of course, you may find a word or two about older versions. Windows 11 version 26H2 is now official. Alongside Windows 11's new preview builds released this week, Microsoft confirmed version 26H2, which is coming later this year as an enablement package based on the same platform as versions 24H2 and 25H2. A newly published blog post details what IT admins should do to prepare for the upcoming launch. Next, we have new Windows 11 bugs. Users report that this month's security updates for Windows 11 cause all sorts of issues, including BitLocker bugs, OneDrive issues, black screens of death, and third-party integration in Office apps. Microsoft has not confirmed those yet, but it acknowledged other issues with its operating system. What Microsoft has confirmed is a bug where Recycle Bin delete prompts display internal file names instead of actual ones, and a year-old Windows JScript compatibility bug caused by security-focused engine changes. Moving to more positive news, Microsoft and Adobe are working on improving Windows performance in popular creative apps like Photoshop. Thanks to SPGO optimizations, users can expect up to 20% better performance. Finally, we have a few useful articles that can help you recover your PC or make it perform better. For one, we published a guide detailing what to do if your computer cannot boot after a clean Windows 11 install. There are two important steps you can try to get your system back to working in no time. Additionally, there is a more detailed guide on various CPU performance modes that could notably improve performance. Windows Insider Program Here is what Microsoft released for Windows Insiders this week: Builds Canary Channel Builds 28120.2315 and 29613.1000 These two builds include a new built-in audio driver, improvements to audio Settings, and more. Dev Channel Builds 26300.8697 and 26220.8690 Not much is available here. Some File Explorer improvements, Start menu enhancements, bug fixes, and more. However, build 26300.8697 is now officially marked as version 26H2. Updates are available This section covers software, firmware, and other notable updates (released and coming soon) delivering new features, security fixes, improvements, patches, and more from Microsoft and third parties. This week, Microsoft announced its newest Surface devices powered by Qualcomm's latest Snapdragon X2 processors. There is the 12th-gen Surface Pro and the 8th-gen Surface Laptop. Both devices feature little to no visual differences compared to their predecessors from 2024, and most changes hide inside, including a better processor, faster graphics, enhanced NPUs, and more. The Surface Laptop also received a new haptic trackpad. Mozilla is currently working on a major Firefox redesign, and earlier this week, it published a roadmap of upcoming features and highlights of the upcoming "Project Nova" rework. Files, one of the best file managers for Windows 10 and 11, has been updated in the Preview channel with a long-requested feature. Tree View is finally available in version 4.1.4, allowing you to quickly browse deeply nested folders without leaving the main view. In addition, the update improved the Windows Fonts folder, allowing you to preview each font without opening the default viewer. Rufus, another useful Windows 11 utility, also received a notable update. Version 4.15 arrived as beta with important fixes for silent Windows 11 installation. It also includes patches for ARM-based Windows PCs, OneDrive removal improvements, and more. Here are other updates and releases you may find interesting: Microsoft faces shareholder lawsuit over masking AI costs and slowing Azure growth Microsoft now allows you to tweak Visual Studio to new extremes Microsoft brings Planner Agent to all Microsoft 365 Copilot users Microsoft fixes one of Excel Copilot's most frustrating limitations Microsoft will finally let you sign in to Edge with a Google account Here are the latest drivers and firmware updates released this week: NVIDIA 610.62 with support for Empulse and various fixes. Reviews are in Here is the hardware and software we reviewed this week Earlier this week, we reviewed the DuRoBo Krono, a portable, phone-sized e-reader with some interesting physical controls. This device has an Apple Watch-like dial for page turning, frontlight adjustment, and more. Software is simple and no-nonsense, but it also lacks some useful features and customization. Overall, the device proved interesting, but not flawless. On the gaming side Learn about upcoming game releases, Xbox rumors, new hardware, software updates, freebies, deals, discounts, and more. Forza Horizon 6 received two big updates this week. Alongside the Series 2 content update, developers pushed plenty of bug fixes and balancing tweaks. However, they also had to acknowledge the Eliminator CR-farming exploit and shut down the online mode temporarily. Luckily, only a few days later, another fix arrived, which re-enabled Eliminator and patched the exploit. Microsoft announced new games for Game Pass subscribers. Those include EA Sports FC 26, Junkster, Call of Duty: Vanguard, Abyssus, RV There Yet?, and more. Some existing games are leaving the catalog, so be sure to check out the full list here. New games are also available for GeForce NOW subscribers, and they include Embers of the Uncrowned Demo, Aphelion, Megastore Simulator, OPERATOR, Citizen Sleeper, and more. Rockstart Games had plenty of GTA-related news this week. For one, the company gave GTA V players another free update. Those still playing the game on Xbox One and PlayStation 4 are no longer required to pay $40 to upgrade to the latest-gen version. More importantly, Rockstar Games revealed the GTA VI cover art and announced the preorder date. The Epic Games Store is giving away two games: Citizen Sleeper and Roboeat. These two titles are up for grabs until next Thursday, but if they are not up to your taste, you can always check out the latest Weekend PC Game Deal issue, which is usually full of discounts and specials that let you save a lot of money on new games. Great deals to check Every week, we cover many deals on different hardware and software. The following discounts are still available, so check them out. You might find something you want or need. GEEKOM X16 Pro at GEEKOM - $1,119.67 | 17% off Acer 4K Webcam for PC/Mac with All-Metal Unibody Sculpted - $59.99 | 14% off Samsung 990 PRO SSD 2TB - $369.99 | 42% off Nothing Ear Wireless Earbuds Bluetooth - $73.15 | 51% off PowerColor Reaper AMD Radeon RX 9070 16GB - $579.99 | 17% off This link will take you to other issues of the Microsoft Weekly series. You can also support Neowin by registering for a free member account or subscribing for extra member benefits, along with an ad-free tier option.
  • Recent Achievements

    • Week One Done
      Supreme Spray LV earned a badge
      Week One Done
    • One Month Later
      Genuinetonerink- Dubai earned a badge
      One Month Later
    • Week One Done
      Genuinetonerink- Dubai earned a badge
      Week One Done
    • One Year In
      hhgygy earned a badge
      One Year In
    • Week One Done
      AMV earned a badge
      Week One Done
  • Popular Contributors

    1. 1
      +primortal
      506
    2. 2
      +Edouard
      163
    3. 3
      PsYcHoKiLLa
      84
    4. 4
      Steven P.
      74
    5. 5
      Michael Scrip
      71
  • Tell a friend

    Love Neowin? Tell a friend!