1.    12 Jul 2017 #1
    Join Date : Oct 2015
    Posts : 10
    Windows 10

    Automatically deny access of (Drives) to newly created user accounts


    Hello,

    Firstly, hope I'm posting in the right section.

    I would like to know if this is actually possible, i.e. the ability to deny complete access of a specific drive/partition to a newly created user account (local) somewhere in the advanced security settings or via cmd. The current situation is that I have to manually access the advanced security tab of the concerned drive/partition, add/edit the new user account(s) and then deny access to them individually, requiring too many mouse clicks and admin password inputs each time.

    What I prefer instead is to be able to set up the security settings in a manner that would auto-disable access to all user accounts likely created in the future and allow access to only the currently enabled local/admin account.

    Thanks in advance.
      My ComputerSystem Spec
  2.    12 Jul 2017 #2
    Join Date : Jul 2016
    Crewe Cheshire
    Posts : 1,451
    windows 10

    Welcome to the forum. Is this for a company and do you have a domain?
      My ComputerSystem Spec
  3.    13 Jul 2017 #3
    Join Date : Oct 2015
    Posts : 10
    Windows 10
    Thread Starter

    Thank you.

    Actually, it's neither. It's just for my personal use. I just want the access denial for any guest/local accounts I may create in the future and not have to worry about the regular drill ( as in my opening post). Also, I'm on the Home edition, so not part of any domains.
      My ComputerSystem Spec
  4.    15 Jul 2017 #4
    Join Date : Oct 2015
    Posts : 10
    Windows 10
    Thread Starter

    I guess it's safe to assume my requirement isn't possible since there are no more replies.

    edit: I found an alternative solution (via CMD) on your Windows 8 forums. Although not automatic, it greatly reduces the steps involved but can't seem to get it to work for some reason. It's as shown below:

    C:\WINDOWS\system32>icacls "s:" /grant "GUEST 2":N /T
    Invalid parameter "GUEST 2:N"

    C:\WINDOWS\system32>icacls "c:" /grant "GUEST 2":N /T
    Invalid parameter "GUEST 2:N"

    Tried prefixing the user name with the system name, i.e, "system name\GUEST 2":N /T. Also tried with other user names and still get the same error. Can't seem to figure out what the issue is.

    Any help's appreciated.
    Last edited by BRAC; 16 Jul 2017 at 05:57.
      My ComputerSystem Spec
  5.    25 Jul 2017 #5
    Join Date : Oct 2015
    Posts : 10
    Windows 10
    Thread Starter

    This complete silence is rather baffling. I would appreciate a reply to the ICALS bit, at least. If not please feel free to close the thread.

    Many of us seek help here or other third party sites as the Windows forums are mostly useless with automated replies, mostly by those hanging on their dear jobs despite being incompetent.
      My ComputerSystem Spec
  6.    25 Jul 2017 #6
    Join Date : Jul 2015
    Posts : 3,694
    10 Pro

    For icacls you want to deny all access rather than granting none.

    Code:
    C:\Windows\system32>net user
    
    User accounts for \\MACBOOK
    
    -------------------------------------------------------------------------------
    Hali                     Administrator            DefaultAccount
    dillo                    Guest                    guest 2
    The command completed successfully.
    
    
    C:\Windows\system32>icacls c:\temp /deny "guest 2":f
    processed file: c:\temp
    Successfully processed 1 files; Failed processing 0 files
    
    C:\Windows\system32>icacls c:\temp
    c:\temp MACBOOK\guest 2:(N)
            MACBOOK\Hali:(OI)(CI)(F)
            BUILTIN\Administrators:(OI)(CI)(F)
            NT AUTHORITY\SYSTEM:(OI)(CI)(F)
    
    Successfully processed 1 files; Failed processing 0 files
    
    C:\Windows\system32>


    Assuming your guest 2 user is a limited user (and not part of administrators group) then they will not be able to see other users files anyway. Denying access to volumes other than C would not be an issue but I really don't know what would happen if you tried to deny access to a user to the whole of the C drive. It would fail on paths you weren't authorized to for sure and taking ownership to overcome this would probably not be wise.
      My ComputerSystem Spec
  7.    25 Jul 2017 #7
    Join Date : Oct 2015
    Posts : 10
    Windows 10
    Thread Starter

    @lx07

    Thanks a lot for your time.

    That minor change (which I never knew of) from grant to deny did the trick. And, you're right about C: drive being denied access. Also, you mentioned files not being accessible by guest users not part of administrator groups. In my case I was still able to navigate those drives when signed in as a guest. Anyway, all's well now.

    Thanks again.
      My ComputerSystem Spec

 


Similar Threads
Thread Forum
Solved How to move User Folder and Restrict Access to other Drives/Partition
Hi, everyone. I just recently joined this forum with the intent of getting help in setting up a new computer. I've done a fair share of research in this (and other) forum, but the variety of solutions I found left me confused more than ever. I...
Installation and Upgrade
Solved Will deleting administrator user also delete accounts created with it?
I have a single administrator account. I've created local users with it. The local accounts function perfectly. However, the administrator account has become progressively less stable. I'd like to delete it and replace it with a fresh account. How...
User Accounts and Family Safety
Access to downloaded store games for all user accounts?
Hi - this user accounts area has stumped me - can you help? I have downloaded a number of games from the Microsoft store. But on my pc I have a child user account for my three children via the Microsoft family accounts windows 10 online software....
User Accounts and Family Safety
Deny anyone & anything 'permissions' to access my work computer
Thanks to the help I've recieved here I'm about to reset my laptop to factory defaults (clean sweep) and then I would like to deny all permissions to everyone,anyone,anything, and eveything except me. ACCESS DENIED What is the simplest most...
General Support
Solved Access user accounts
I have forgotten an administrator account password and am not even able to get past the "user accounts" in Control Panel" without it. I don't log on to Windows with this account anyway!
User Accounts and Family Safety
Our Sites
Site Links
About Us
Windows 10 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 10" and related materials are trademarks of Microsoft Corp.

Designer Media Ltd
All times are GMT -5. The time now is 21:33.
Find Us
Twitter Facebook Google+ Ten Forums iOS App Ten Forums Android App



Windows 10 Forums