Data Recovery Case File · Formatted & Logical Faults · The OneDrive Folder Paradox
Visible everywhere, openable nowhere: the three real reasons files "only open inside Windows" — permissions, encryption, and placeholders — his scepticism of "the drive is broken" vindicated, and the files brought out properly
His enquiry contained a paradox, an incorrect verdict, and a well-placed doubt. The background: a Windows 10 laptop whose system corrupted during an update; he extracted the drive and "salvaged what I can." The paradox: "there are some files saved in the OneDrive folder; they haven't backed up to OneDrive online; they can't be accessed from the drive directly by connecting it to another PC — they can, allegedly, only be accessed from within Windows." The verdict he was given: a local repair shop said "the hard drive is broken." And the doubt: "which I find hard to believe, when I can access the file system and all files from another computer — but then I'm no hardware expert." His instinct outranks the verdict: a drive whose entire filesystem reads cleanly from another machine is, to a first approximation, not broken — and files that are visible everywhere but openable only "inside Windows" point to three specific, well-understood mechanisms, none of which is hardware. This page names all three, and the road that brought his files out.
| Media | Windows 10 laptop hard drive — system corrupted during an update; drive extracted; filesystem fully readable from another PC except files within the OneDrive folder |
| Reported situation | OneDrive-folder files never synced to the cloud · visible from a second PC but failing to open · third-party verdict of "broken drive" doubted by the owner · important files sought |
| Fault class | Account-bound access barrier on a healthy drive — NTFS permissions, Windows account encryption, or sync placeholders; not a hardware fault |
| Equipment used | Drive imaged write-blocked (Atola TaskForce 2) · file-attribute analysis distinguishing permissions / encryption / placeholder states · OSForensics extraction reading past NTFS permissions · Passware Kit Forensic standing by for account-encrypted files with the owner's own credentials · verified delivery |
The decode: the three mechanisms behind "only inside Windows"
First — and most likely — NTFS permissions: every file on a Windows drive carries an access-control list naming who may open it, and files in a user's profile — the OneDrive folder included — are typically locked to that user's account. Connect the drive to another PC and the filesystem reads fine (his observation, exactly), but opening those files fails: the second machine's account isn't on the list, so Windows refuses — "access denied" dressed in various costumes. It looks mysterious; it's bureaucracy. And it is entirely solvable, because permissions are an operating-system courtesy, not a property of the data: recovery tools that read the disk directly simply aren't bound by them, and extract the files as plainly as any others.
Second — account-tied encryption: Windows can encrypt files or profiles against the account's own credentials, and encrypted files show precisely his symptoms: visible entries, unopenable content anywhere the account's keys aren't present. This is the sterner mechanism — real cryptography, not courtesy — and the honest position this archive always states applies: it's addressed with the owner's own credentials, the legitimate keys recovering legitimate access, and a strong key genuinely lost is a limit no honest lab talks around. The diagnosis between this and permissions takes minutes on an image: the file attributes say which barrier is standing.
Third — sync placeholders: modern OneDrive can display cloud files as local-looking placeholders — entries with names and sizes whose bytes live online until summoned. Files that never synced can't be placeholders of anything, so his description argues against this one — but it belongs in the list because it's the variant where the local drive genuinely holds nothing, and honest triage rules it in or out by reading the entries' actual on-disk nature rather than assuming.
What the shop's verdict got wrong: no blame required — a counter that sees "files won't open" without tools to read attributes reaches for the nearest big explanation. But the evidence he himself gathered refutes it: a fully readable filesystem is a functioning drive, and his "I find that hard to believe" was the correct engineering response. Scepticism, when you hold contradicting evidence, is not presumption — it's diagnosis.
On the bench
The drive was imaged write-blocked on the Atola TaskForce 2 — its cleanly-reading state preserved — and the paradox was resolved by reading what the files actually were: attribute analysis on the image distinguishing permission locks from encryption flags from placeholder entries. The finding directed the road: OSForensics extracted the permission-bound files directly from the image, unbound by the account courtesies that had stonewalled the other PC — and for any account-encrypted members, Passware Kit Forensic stood ready to apply his own credentials, the legitimate-keys route this archive works and the honest limit it names. The OneDrive folder's contents came out, were verified by opening on a machine that had never held his account, and were delivered — the "broken" drive having read every byte without complaint.
The outcome
The unsynced OneDrive-folder files recovered from the healthy drive, verified and delivered — his doubt vindicated in full. Free assessment, one fixed written figure including VAT, no recovery, no fee. The paradox, mapped for everyone told a readable drive is "broken": files visible everywhere but openable only inside Windows are behind permissions, account encryption, or placeholders — bureaucracy, cryptography, or mirage — the first yields to direct extraction, the second to your own credentials honestly applied, and the third to knowing before you hope. And a filesystem you can browse from another machine is a drive that's fine; trust that evidence, as he did.
Files visible from another PC but refusing to open
Don't accept "the drive is broken" if you can browse the whole filesystem — a readable drive is a working drive, and files that open nowhere but their home Windows are behind one of three barriers: NTFS permissions (most likely; solved by extraction tools that read the disk directly), account-tied encryption (solved with your own credentials — keep them; a truly lost key is a real limit), or cloud placeholders (entries whose bytes live online — check whether they ever synced). Don't take ownership of the files on the new PC by force-editing permissions across a whole profile; on the only copy, mistakes cascade. Image first, identify which barrier is standing, then open it the right way.
That's a barrier, not a breakage — call Edinburgh Data Recovery on 0131 202 0491; imaged, diagnosed by attribute, extracted past the lock with your authority — one written figure, no recovery, no fee.
Request a quote online →
Our case files are drawn from genuine enquiries received by our laboratory over the past ten years, anonymised to protect client confidentiality. Each one describes the diagnostic and recovery procedure our engineers apply to that fault, using the equipment listed.