Add the local user to the local administrator's group or local power users group (depending on what type of rights you want the user to have). First, unhide all hidden folders and files, or you will have problems with system files. Remove the everyone group from all partition NTFS rights. Add the groups Local/powerusers, Local/administrators, Creator, Owner and System to have full control and reset permissions on all folders and files (Local group will be the computer you are locking down). This will restrict all files to members of the groups above and permit someone from hacking in and changing or deleting important files.
For more information on this topic, visit these other SearchSecurity resources:
Best Web Links: Securing Microsoft
This was first published in June 2002