ProcMon is an indispensable tool that zillions of people have used. Here are some easy steps for starting, stopping, and saving a Procmon capture.
When the capture is stopped, a red slash mark should appear across the icon of the magnifying glass.
One of the most basic, common, and first things I usually do is to set a filter on the procmon results that searches the results column for "Access Denied."
Start by clicking the icon (or CTRL+L) that looks a bit like a coffee filter or snow cone as seen below. . .
Toggle the first two options to RESULT + CONTAINS. Type in the word DENIED into the blank field. Click ADD and click APPLY.