https://learn.microsoft.com/en-us/defender-endpoint/enable-c... this works surprisingly well to prevent an app from going too far into folders it should not access.
It's a bit opaque though, not as simple as *nix owner/group/everyone permissions.
It's a bit opaque though, not as simple as *nix owner/group/everyone permissions.
I may "trust" a video editing app, for example, so I can access my raw content folders. It should still be completely impossible for that process (or any spawned from it) to access my browser session information in case of an RCE from loading a malicious video.