Permission setting


We have under DC environment. My boss asks me to give our phone service vendor a remote access to a pc that handle our phone system.

I know I have to create a domain user for this person.  My question is how I can prevent this person to go on our shared drive or other pc on the network.  thanks

ps. This pc is still on XP  :)
Active DirectoryWindows Server 2003

