я делал так:
gpedit.msc, далее такое:
1.UC/Administrative Templates/Windows Components/Windows Explorer/Hides the Manage item on the Windows Explorer context menu - enabled
2.UC/Administrative Templates/Windows Components/Windows Explorer/Prevent access to drives from My Computer - enabled
3.UC/Administrative Templates/Windows components/Windows Explorer/Turn off Win+X hotkeys - enabled
4.UC/Administrative Templates/Start Menu and Taskbar/Remove links and access to Windows Update - enabled
5.UC/Administrative Templates/Start Menu and Taskbar/Remove common program groups from Start Menu - enabled
6.UC/Administrative Templates/Start Menu and Taskbar/Remove My Documents icon from Start Menu - enabled
7.UC/Administrative Templates/Start Menu and Taskbar/Remove Document menu from Star Menu - enabled
8.UC/Administrative Templates/Start Menu and Taskbar/Remove programs on Settings menu - enabled
9.UC/Administrative Templates/Start Menu and Taskbar/Remove Search menu from Start Menu - enabled
10.UC/Administrative Templates/Start Menu and Taskbar/Remove Help menu from Start Menu - enabled
11.UC/Administrative Templates/Start Menu and Taskbar/Remove Run menu from Start Menu - enabled
12.UC/Administrative Templates/Start Menu and Taskbar/Add Logoff to the Start Menu - enabled
13.UC/Administrative Templates/Start Menu and Taskbar/Remove Drag-and-drop context menus on the Start Menu - enabled
14.UC/Administrative Templates/Start Menu and Taskbar/Prevent changes to Taskbar and Start Menu Settings - enabled
15.UC/Administrative Templates/Start Menu and Taskbar/remove access to the context menus for the taskbar - enabled
16.UC/Administrative Templates/Start Menu and Taskbar/remove pinned programs list from the Start Menu - enabled
17.UC/Administrative Templates/Start Menu and Taskbar/remove frequent programs list from the Start Menu - enabled
18.UC/Administrative Templates/Start Menu and Taskbar/remove All Programs list from the Start Menu - enabled
19.UC/Administrative Templates/Start Menu and Taskbar/remove user name from Start Menu - enabled
20.UC/Administrative Templates/Start Menu and Taskbar/Hide the notification area - enabled
21.UC/Administrative Templates/Desktop/Hide and disable all items on the desktop - enabled
22.UC/Administrative Templates/Desktop/Remove My Computer icon on the desktop - enabled
23.UC/Administrative Templates/Desktop/Remove the Desktop Cleanup Wizard - enabled
24.UC/Administrative Templates/Control Panel/Prohibit access to the Control Panel - enabled
25.UC/Administrative Templates/Control Panel/Display/Password protect the screen saver - disabled
26.UC/Administrative Templates/Control Panel/Display/Screen Saver - disabled
27.UC/Administrative Templates/System/Ctrl+Alt+Del Options/Remove Task Manager - enabled
28.UC/Administrative Templates/System/Ctrl+Alt+Del Options/Remove Lock Computer - enabled
29.UC/Administrative Templates/System/Ctrl+Alt+Del Options/Remove Change Password - enabled
НО перед этим вставлял ярлык 1С в "Пуск" (только от-туда можно что-либо запустить) и прописуем БД заранее.
А чтоб политики не распространялись для админа так:
http://forum.oszone.net/thread-98546.html (4-ый пост)
правда делал для терминального, но и так должно работать.