My personal laptop (Windows 11 25H2) has 2 accounts: Admin and Bot
net user Bot shows Bot is in localgroup Users and in no other groups
net user Admin shows Admin is in localgroup Administrators, Performance Log Users, and in no other groups
I want to disable Bot's access (read/write/execute/...) to all files/directories except for his home C:\Users\Bot and system like C:\Windows. For this question, I want to disable Bot's access to D:\
Here is what I did:
This PC > Right click D: drive > Properties > Security > Edit > Choose Users and checks all checkboxes under Deny > OK
I checked that I did choose Users, not Administrators
The result is both Admin and Bot cannot access D:\
Running takedown /F D:\ /R /D Y or icacls D:\ /reset /T /C as administrator doesn't work. I tried booting the laptop in Safe Mode, but these commands still failed
My questions:
- Why is Admin affected? Does Admin belong to Users somehow? How to know about that, since
net user Admin doesn't show it?
- What's the correct way to disable Bot's acccess to D:, without affecting the Admin account?
Thanks very much!