Find locking programmes
Identifies processes holding files or folders open when Windows exposes the owner, including PID and executable path.
Find out why Windows said no.
AccessWhy is a small, read-only diagnostic utility for files and folders. Drop in the troublesome item, tell it what Windows would not let you do, and it separates permissions, live locks, security controls and storage conditions into a plain-English result.
Windows can deny the same action for very different reasons. AccessWhy checks the live operation and the surrounding evidence instead of assuming every error is an ACL problem.
Identifies processes holding files or folders open when Windows exposes the owner, including PID and executable path.
Shows when your permissions allow an operation but a live sharing lock is preventing it right now.
Checks Mark of the Web, Authenticode signature state and relevant application-control evidence.
Looks for recent Defender Controlled Folder Access, AppLocker and Code Integrity blocks where Windows records them.
Recognises read-only volumes, removable drives, network paths, mapped shares, OneDrive-style cloud placeholders and reparse points.
Produces a redacted support report while keeping the full local technical evidence available when you need it.
Your permissions: allowed
Current availability: blocked by Microsoft Word
Why: Windows reports a live sharing lock. Close the programme and use Re-check.
AccessWhy is deliberately conservative. The normal diagnostic path does not take ownership, rewrite ACLs, kill processes, close another programme's handles, alter Defender settings or modify the selected file.
That makes it suitable for diagnosing a problem without turning the diagnostic tool itself into another source of changes.
AccessWhy is a new, currently unsigned Windows utility. A SmartScreen reputation warning is not the same thing as an antivirus engine reporting a named threat. Check which message Windows is actually showing before deciding what to do.
This is normally Microsoft Defender SmartScreen saying that the downloaded executable or its publisher does not yet have enough reputation. Microsoft documents file-hash and publisher reputation as separate SmartScreen signals.
Treat that as an antivirus detection, not merely a reputation prompt. Do not switch off Defender or another antivirus just to run AccessWhy.
The original v1.0.0 executable was flagged by 2 of 70 VirusTotal engines with generic/heuristic labels. That prompted a code-level cleanup rather than simply dismissing the detections. v1.0.1 removes the old global system-handle scanner and removes PowerShell, whoami, icacls, clip.exe and reg.exe helper use. AccessWhy now uses narrower native Windows APIs for those jobs. It still performs legitimate diagnostic operations such as asking Windows which process is using a file or folder, so heuristic results should always be checked against the exact release hash and current scan.
Hashes below apply only to AccessWhy v1.0.1 as published here. Compare them before relying on a warning override or antivirus exception.
dcf1ba4b5dddc6334e6eb7d47f6a9d44f65c83d8d0a326edb0bf06bd8a8d3d44
4fbdb4e3c3c28c5b500aa97e45886aed86246baeceec1920af53908c9d9d2b8f
Open the live VirusTotal page for this exact SHA-256. If the build has not yet been analysed there, VirusTotal will offer to analyse it. Results can change as security engines update, so the live hash page is more useful than a hard-coded score.
Check this exact build on VirusTotal ↗AccessWhy.exe with the value above. A multi-engine scan is useful additional evidence, but it is not a guarantee by itself.No installer is required. Extract the ZIP and run AccessWhy.exe. You can drag a file or folder onto the window, browse for one, or optionally add a Diagnose with AccessWhy item to the Windows Explorer right-click menu from the About screen.
Choose or drag in the file, folder or drive that Windows refused to work with.
Open, save, create, delete, rename/move, run, or let AccessWhy test the common operations.
The plain-English result comes first. Raw ACL, token and Windows evidence stays behind Technical details.
The current release is recommended, but previous release ZIPs remain downloadable so hashes, reports and behaviour can be reproduced later.
Security-cleanup release. Removed the old global handle scanner and removed PowerShell, whoami, icacls, clip.exe and reg.exe helper use. Native Windows APIs now handle event logs, signing checks, ACL evidence, clipboard and Explorer integration.
dcf1ba4b5dddc6334e6eb7d47f6a9d44f65c83d8d0a326edb0bf06bd8a8d3d44
ZIP SHA-256
4fbdb4e3c3c28c5b500aa97e45886aed86246baeceec1920af53908c9d9d2b8f
First stable release. Historical VirusTotal check showed 2/70 engines flagging generic or heuristic detections. It remains available for reproducibility, but v1.0.1 is the recommended download.
0aa405d5aab1a90e514e40744e9c23a19f262f1becfd9423d8257c5680236a05
ZIP SHA-256
fae231e35cf98b570351b0e71e2b66e47fb1bcaae5ed938d147813a00682547b
Windows x64. Portable. Self-contained. Created by Liam Jordan and provided free forever.