How to disable an account's access to D:\?

ZL F 0 Reputation points
2026-08-30T02:17:36.8466667+00:00

My personal laptop (Windows 11 25H2) has 2 accounts: Admin and Bot

net user Bot shows Bot is in localgroup Users and in no other groups

net user Admin shows Admin is in localgroup Administrators, Performance Log Users, and in no other groups

I want to disable Bot's access (read/write/execute/...) to all files/directories except for his home C:\Users\Bot and system like C:\Windows. For this question, I want to disable Bot's access to D:\

Here is what I did:

This PC > Right click D: drive > Properties > Security > Edit > Choose Users and checks all checkboxes under Deny > OK

I checked that I did choose Users, not Administrators

The result is both Admin and Bot cannot access D:\

Running takedown /F D:\ /R /D Y or icacls D:\ /reset /T /C as administrator doesn't work. I tried booting the laptop in Safe Mode, but these commands still failed

My questions:

  1. Why is Admin affected? Does Admin belong to Users somehow? How to know about that, since net user Admin doesn't show it?
  2. What's the correct way to disable Bot's acccess to D:, without affecting the Admin account?

Thanks very much!

Windows for home | Windows 11 | Files, folders, and storage
0 comments No comments

3 answers

Sort by: Oldest
  1. Ivan B 124.5K Reputation points Independent Advisor
    2026-08-30T03:49:06.8433333+00:00

    Hi,

    I'm a bit confused—is the "bot" account a standard user account?

    In the properties for the D: drive, you should add the Administrators group and remove the Users group (keeping only the standard/default ones). Could you take a screenshot of the Security tab and post it here?

    Thanks.

    Was this answer helpful?

    0 comments No comments

  2. Craig Long 18,640 Reputation points
    2026-08-30T20:38:48.5033333+00:00

    If both accounts are personal, you can use the OneDrive Personal Vault to lock out other users.

    If the drive is encrypted with BitLocker and can only be opened by entering the PIN or recovery key each time, then it is well protected. Encryption is the only way to securely lock out other users.

    Was this answer helpful?


  3. ZL F 0 Reputation points
    2026-09-21T09:01:59.1666667+00:00

    Here is what finally works on my machine:

    1. Explorer > Right click D: drive > Property > Security > Edit
    2. Add user Bot > OK
    3. Select Bot (double check it's not other groups or users), check all boxes in Deny column > OK

    Now Bot cannot access D: drive while others can

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.