I have to prevent an administrator account from modifying a file, especially the hosts file (C: Windows System32 Drivers etc hosts). I would like this admin account to retain all normal administrator permissions, but can not modify the hosts file. I have written a guide on how to proceed in Ubuntu and I would like to do something similar in Windows 10.
I understand that it will not be bullet-proof, but I would like something that makes it annoying enough to modify this file.