Since you tagged nVidia Gamestream, if you have a launcher for the games you want your friend to have access to, you could think about replacing the Windows shell (sort of the desktop environment) with the Gamestream Client.
To turn on Shell Launcher in Windows features
- Go to Control Panel > Programs and features > Turn Windows features
on or off.
- Expand Device Lockdown.
- Select Shell Launcher and OK.
https://docs.microsoft.com/en-us/windows/configuration/kiosk-shelllauncher
Please be aware that this is not 100%. It doesn't block access to files, it only makes it harder for them to get to. For example, if a game or the launcher has an "open files" dialog, your friend would still be able to access your files, etc. Something that's even 100% close to blocking access to resources like this is impossible on Windows or would require a great deal of configuration with Group Policies.