An accounting firm shut out of an external they could see perfectly well. One question settled the entire job, it takes about thirty seconds to answer, and only one of the two possible answers has a way forward.
An accounting company kept client records, invoices and tax data on an Iomega external used as their working backup. One morning Windows began returning “Access is denied” to everyone. The drive was detected, appeared in Explorer, and let nobody in. Their accounting software could not read from it either, and attempts to change permissions through the Windows security tab failed.
They stopped there rather than persisting, which was correct — forcing ownership changes across a volume whose file system may be damaged can make matters considerably worse.
Access-denied has two completely different causes that look identical from the desktop, and they have completely different endings. One is usually a two-minute fix. The other has no fix at all without the key.
The distinction is settled by looking at the volume’s first sector rather than by trying things.
An NTFS volume opens with a boot sector carrying NTFS as its OEM identifier. A BitLocker volume does not: BitLocker replaces that sector with its own, carrying the signature -FVE-FS-, followed by metadata describing the encryption and the key protectors in use. The two are trivially distinguishable, and reading a boot sector modifies nothing.
Here the identifier was NTFS, plainly, with a valid parameter block behind it and recognisable file-system structures beyond that. Not encrypted. Which meant the data was intact and reachable, and the fault was in the records governing who may reach it.
Worth stating the counterfactual plainly, because it is the honest half of this page: had that sector said -FVE-FS- with no recovery key available anywhere, the answer would have been no. Encryption cannot be undone by us or by anyone without the key, and we would have said so at the free diagnostic rather than after a bill.
NTFS does not store a permission list inside each file. It stores a security descriptor — owner, group, and the access control entries naming who may do what — in a shared metafile, and each file record simply points at the descriptor that applies to it. Identical permissions across ten thousand files cost one descriptor, not ten thousand.
That design is efficient and it is also the failure mode. Damage the shared structure and every file pointing at it becomes unopenable simultaneously, which is exactly what the firm experienced: total, sudden, and affecting everything at once.
Compounding it, the entries name accounts by security identifier — a value unique to an account on a particular machine or domain, not a username. Move a drive to a rebuilt computer and the descriptors reference identifiers that no longer resolve to anybody. Windows then denies access correctly, because as far as it can tell the owner does not exist.
Inside the Iomega enclosure was an ordinary Western Digital drive, mechanically healthy throughout — no reallocated sectors, no pending sectors, nothing in its history to suggest media trouble.
The drive was imaged sector by sector behind a hardware write blocker before anything was attempted, so no subsequent step could alter the original. Everything afterwards ran against the copy.
From the image, surviving security descriptors were read directly and the damaged shared structures reconstructed, with ownership reassigned to a valid account. The underlying file data was never touched — this is a metadata repair, and the contents of the files were never in question.
Directory metadata that had become inconsistent was rebuilt using the file system’s own redundancy: NTFS keeps a mirror of the first records of its master file table at a separate location precisely so that damage to one copy is survivable.
Opening files was not sufficient here. The firm’s accounting package was the actual test, because a spreadsheet that opens in Excel but that the accounting software will not import is not a successful recovery for an accountant.
Tax records, invoices and payroll data were confirmed readable by the applications that needed them before anything was signed off.
Complete, returned on fresh media, in four working days. Nothing had ever been physically wrong with the disk — the entire failure was a set of damaged permission records standing between a firm and their own data.
The useful takeaway is about triage. On a drive moved between machines, or one from a computer since rebuilt, “access denied” is normally an ownership problem, and taking ownership through the Windows security tab often resolves it in two minutes at no cost. Where that fails, stop — the file system may be damaged and forcing it repeatedly makes the eventual repair harder. And check the boot sector before assuming either way. A single external drive is from £300 +VAT after a free 48-hour diagnostic.
Post it or bring it in. Either way the diagnostic costs nothing and commits you to nothing, and you get one figure in writing before a single screw is turned.
Nothing can begin until the device is on the bench, which makes this the only step that needs anything from you. Pack it properly, put your details in with it, and send it over. What follows is a free diagnostic and a written figure, in that order.
Posting it? Use something tracked and insured — whatever is on the drive is worth considerably more than the postage. Bringing it in? Weekdays, 9am to 5:30pm, and it still wants packing as above for the journey.
Tell us what the device is, what it is doing, and anything already tried — an engineer will come back with a realistic view of the odds and a price band, before you commit to posting anything.
We’ll get back to you soon. Anything pressing, call 0161 871 0788.
Almost always that the security descriptors name an account that no longer exists. NTFS identifies owners by a value unique to one machine or domain, so a drive moved to a rebuilt computer points at somebody Windows cannot find, and it refuses access correctly — on data that is completely intact.
Frequently, and it costs nothing to try. Right-click the drive, Properties, Security, Advanced, take ownership and apply it down through the subfolders. If it works you are finished. If it fails, stop — the file system itself may be damaged, and forcing ownership repeatedly makes the eventual repair harder rather than easier.
Then it is a different job with a different ending, which is why we settle it first. BitLocker, FileVault and third-party encryption cannot be opened without the key, by us or by anyone, and any firm implying otherwise is describing something that does not exist.
By reading the volume’s first sector, which takes seconds and changes nothing. An NTFS volume announces itself with NTFS as its identifier; a BitLocker volume carries a different signature entirely. One is often a two-minute fix, the other has no fix without the key — so it is worth establishing before anyone spends money.
From £300 plus VAT for a single external drive, quoted in writing after a free 48-hour diagnostic. Send the unit complete with its enclosure rather than removing the disk inside.
Kick off with an instant online quote, or ring us and talk it through first. Either way you’ll know a clear, fixed price before any work starts.