Assuming pro, it really is easier to just create a guest account(s) that is a "standard user" and his folders automatically get walled off from those users. IF he has folders/drives outside his user folder structure that he also wants to deny access, it's as easy provided he has any organization whatsoever of his filesystem - the key term there is organization; no granular security plan is clear and simple if the filesystem is messy an unorganized.
__________________
Music is what feelings sound like.
|