I followed the discission from above, but I cannot see where is the difficulty.
Using Group POlicy you have all necessary tools to lock down that desktop.
I just did a huge list with possible options that you can use.
If you want I can give write you all those settings.
(but there are a lot, and they are flexible).
One trick is to use "User group policy loopback" with processing mode to "replace". In this way, the GPO specified for the OU where is the computer will be applied with both sections (computer and user) ignoring the actual user location (and his asssociated GPOs).
You can restrict how the "Start" menu will look, you can restrict any icon on your desktop, and if you want to start automatically in IE then you can set a "Custom User Interface" that will be set to IE. And having explorere.exe as forbidden (I cannot test this now, but defining a custom user interface it's a nice idea. I remember that having NetWare you could set as SHELL a different application than explorer).
Then you can have a list with forbidden applications or allowed ones,... etc. There are many Administrative Templates there that can be use for restricting access.
So,... please tell me if you are trying to do such a things. Gia Betiu
m.betiu@chello.nl
Computer Eng. CNE 4, CNE 5