GiliSoft File Lock Pro

Lock selected folders on shared Windows computers and LAN locations

Control who can open a local or reachable network folder, keep approved reference files readable, and add local password-managed protection where Windows sharing alone is not convenient.

  • Lock local, external, and reachable LAN shared folders
  • Separate read access from editing and deletion rights
  • Keep selected folders hidden from ordinary browsing

How to Lock a Folder on a Shared Computer or Network

A shared folder can mean a folder used by several accounts on one PC or an SMB folder opened from several computers. The protection method changes with the location. On one PC, Windows accounts and NTFS permissions are the baseline. Across a LAN, the host also applies share permissions and authenticates the connecting user. File Lock Pro adds a simpler password-managed layer for selected local, external, and reachable shared folders.

Quick answer: use named Windows accounts, grant only the access each person needs, and test the effective result from another account. For an SMB share, review both Sharing and Security. Use File Lock Pro > Shared Folder > Locking File when one selected reachable folder should also be controlled from the File Lock Pro interface.

First Identify What “Shared Computer” Means

SituationStart withWhat it controls
Several people sign in to one PCSeparate standard accounts + NTFS permissionsWhich signed-in users can open or change the folder
Several PCs open \\PC\ShareSMB authentication + share permissions + NTFS permissionsWho reaches the share and what they may do inside it
One selected folder needs a local master passwordRecommended option File Lock ProLocking, hiding, or protecting the selected folder
Users may read but must not edit originalsRead permission or File Lock Pro protectionOpening is allowed while modification is restricted
Sensitive traffic crosses an untrusted networkSMB encryption on supported Windows/Server configurationsProtects SMB data in transit from interception

Do not begin by looking for a universal “folder password” switch. Windows normally protects network shares through user identity and permissions. Decide first whether the folder must be invisible, unreadable, read-only, or merely unavailable to selected accounts.

Before Changing Access, Record the Existing Share

Identify the host computer

Permission changes belong on the PC or server that physically stores the folder, not only on the computer that maps it.

Record the UNC path and owner

Keep the current path, such as \\Office-PC\Finance, and note who should approve future access.

List real users and groups

Prefer named accounts or managed groups over a shared administrator login or a broad Everyone entry.

Keep a verified backup

Permission changes, locking, and encryption are not substitutes for a recoverable copy stored outside the shared folder.

Method 1: Lock a Reachable Shared Folder with File Lock Pro

File Lock Pro includes a dedicated Shared Folder > Locking File workspace. Use it when the LAN folder is already reachable from the Windows PC running File Lock Pro and the selected folder needs an additional password-managed control without changing every other share.

GiliSoft File Lock Pro software box

One interface for local and shared folders

Lock a selected folder to block opening, hide content that should not appear in ordinary browsing, or protect readable files from unwanted changes.

GiliSoft File Lock Pro Shared Folder Locking workspace
The Shared Folder workspace scans reachable LAN locations and provides the Lock Folder action. Open the image to inspect the interface.
  1. Open the shared folder in File Explorer first and confirm the current Windows account can reach it.
  2. Start File Lock Pro and enter the master password.
  3. Choose Shared Folder > Locking File.
  4. Select Lock Folder, add the target shared folder, and apply Set to lock.
  5. Test from the host and from another intended workstation before relying on the rule.
Keep Windows sharing correctly configured. File Lock Pro works with a reachable folder; it does not repair account credentials, a disabled SMB share, offline host computer, or incorrect NTFS permissions.

Method 2: Lock a Folder Used by Several Accounts on One PC

For a family, classroom, front desk, or office PC, each person should have a separate Windows account. Keep daily users as standard users and store private content inside the owner’s profile instead of Public folders.

  1. Create or review accounts under Settings > Accounts > Other users.
  2. Right-click the folder and open Properties > Security > Advanced.
  3. Confirm the owner, inherited entries, and the exact users or groups that currently have access.
  4. Grant only the required rights: Read for viewing, Modify for normal editing, or no access for private folders.
  5. Sign in with the other account and test opening, creating, renaming, and deleting files.
Windows advanced security permissions for a folder
Review inherited permissions before converting or replacing them.
Windows folder permission entries
Use explicit Deny entries sparingly because they can override an expected Allow entry.

Administrator reality: a local administrator can often take ownership and change NTFS permissions. If the administrator is not trusted, use content encryption and protect the recovery material separately.

Method 3: Configure a Windows Network Share for Specific People

Microsoft’s Windows guidance uses Give access to > Specific people for a LAN share. SMB authenticates the connecting user, while Windows evaluates share and file-system permissions before allowing access.

  1. On the host PC, right-click the folder and choose Show more options > Give access to > Specific people.
  2. Add the intended Windows users rather than selecting Everyone unless the share is genuinely public on that LAN.
  3. Assign Read or Read/Write according to the actual job.
  4. Record the displayed network path and connect from another PC using the intended account.
  5. If needed, map the path in This PC > More > Map network drive for repeat access.
Keep LAN shares on trusted private networks. Do not expose SMB ports directly to the public internet. Use an organization-approved VPN or another managed secure access method for remote work.

How Share and NTFS Permissions Work Together

Share permissions apply when the folder is reached through SMB. NTFS permissions apply to the files and folders on the disk. Effective network access is constrained by both layers, so a permissive share does not cancel a restrictive NTFS rule and a restrictive share can limit broader NTFS rights.

1. Authentication

The SMB server identifies the connecting user through Windows credentials.

2. Share permission

The share decides whether that identity may connect and whether access is read-only or change-capable.

3. NTFS permission

The Security tab decides what the identity can do to the actual folder and files.

4. Application or File Lock Pro rule

An additional product rule can lock, hide, or protect selected content.

Choose rights by task

User needTypical accessImportant consequence
View approved documentsReadThe user can normally copy content they are allowed to read.
Create and update filesModifyUsually includes writing, renaming, and deleting.
Manage permissionsFull controlReserve for administrators or data owners.
No folder accessRemove unnecessary Allow accessPrefer clear group membership over complex Deny rules.

When Users Should Read but Not Change the Folder

Reference libraries, templates, approved policies, and training material often need read access without modification. Give consumers Read rights and keep editors in a separate group with Modify rights. File Lock Pro Protecting File is another option when a selected folder should remain readable while common file changes are restricted.

  • Use locking when unauthorized users should not open the folder.
  • Use hiding when the folder should not appear in ordinary browsing.
  • Use protecting when approved users may read but should not change originals.
  • Keep editable drafts separate from approved reference copies.

Stronger Controls for Business File Shares

Least-privilege groups

Assign access through role-based groups such as Finance-Read and Finance-Modify instead of maintaining many individual exceptions.

Access-based enumeration

On supported Windows Server shares, ABE can hide folders a user lacks permission to read. Permissions still provide the actual access boundary.

SMB encryption and signing

Supported SMB configurations can protect network data against interception and tampering. Compatibility depends on client and server versions.

File and share auditing

Audit successful or failed access for sensitive folders only after planning event volume and review responsibilities.

Hiding a share name with a trailing dollar sign or enabling access-based enumeration improves navigation privacy, but neither replaces share and NTFS permissions.

Troubleshoot “Access Denied” Without Weakening the Share

The host is unavailable

Confirm the host PC is on, connected to the same trusted network, and that File and Printer Sharing is allowed for the correct network profile.

Windows uses the wrong credentials

Disconnect the mapped drive and reconnect with the account that was actually granted access.

Share permission allows access but NTFS does not

Review the Security tab and effective access for the exact user or group.

A subfolder inherits unexpected rights

Inspect Advanced Security Settings before breaking inheritance or adding a Deny entry.

An old device asks for SMB 1.0

Do not enable the legacy protocol casually. Update or replace the device and follow current Microsoft security guidance.

Recommended Setup by Shared-Folder Scenario

Family or roommate PC

Separate standard accounts, private profile folders, Windows + L when leaving, and File Lock Pro for selected personal folders.

Small-office LAN share

Named users, specific share audience, NTFS groups, verified backup, and periodic permission review.

Approved document library

Read access for consumers, Modify access for editors, separate drafts, and protection against accidental changes.

Finance or HR records

Least-privilege groups, no broad Everyone access, auditing, encrypted transport where appropriate, and documented recovery.

Shared Folder Security Checklist

  • Use named accounts rather than one shared administrator login.
  • Grant the minimum level of access required for each job.
  • Review both Sharing and Security tabs for network folders.
  • Test opening, editing, renaming, deleting, and copying from another account.
  • Keep SMB shares on trusted networks and avoid direct internet exposure.
  • Back up important data outside the shared or locked folder.
  • Review access after staff, family members, or project roles change.
  • Document File Lock Pro recovery information if product locking is used.

Frequently Asked Questions

Can I put one password directly on a Windows shared folder?

Modern Windows sharing normally authenticates a user account rather than assigning one separate password to each folder. File Lock Pro can add master-password-managed locking to a selected reachable shared folder.

Can File Lock Pro lock a LAN shared folder?

Yes. File Lock Pro includes a Shared Folder Locking workspace for reachable LAN shared folders.

Are share permissions and NTFS permissions the same?

No. Share permissions govern SMB access to the share, while NTFS permissions govern the files and folders on disk. Both can restrict network access.

Does Read permission stop users from copying files?

No. A user who can read a file can generally copy its contents. Do not grant Read access when copying itself is unauthorized.

Can I hide folders users cannot access?

Access-based enumeration can hide unavailable folders in supported shared-folder environments, but share and NTFS permissions remain the actual access control.

Should I use Everyone on a home network?

Use Specific people when privacy matters. Everyone may be acceptable for genuinely public LAN content, but it is not a good default for personal or business records.

Why can a user connect but still receive Access Denied?

The user may pass SMB authentication and share permissions but lack NTFS rights to the target folder, or the subfolder may inherit a more restrictive rule.

Related Shared Folder Guides

Password protect a shared folder on Windows · Shared folder protection on Windows 11 · Make a folder read-only but accessible · Hide files from other users on one PC · File Lock Pro user guide

Protect the folder that matters without closing the whole share

Use GiliSoft File Lock Pro to lock local, external, and reachable LAN folders from one Windows interface.

Download TrialBuy File Lock Pro
Sources and further reading: