• Can you deny access to the windows account linked to sql server? That's how folders / files access works. .cmd is just an exe file AFAIK.

    If the file is part of the sql server install (which I doubt it is), you could just delete the file from the folder. Obviously don't delete the windows version, plenty of things still require it for the server to run correctly.

    No idea what happens if someone tries to activate access and run xp_cmdshell. That might get you anything from an error message to full catastrophic failure.