Windows 10: Is a standard user account necessary for tight security and home user?

Discus and support Is a standard user account necessary for tight security and home user? in AntiVirus, Firewalls and System Security to solve the problem; Is there by any chance you guy's are using Public networks? This could play a big part in what folders are shared by default... Discussion in 'AntiVirus, Firewalls and System Security' started by Kol12, Sep 21, 2016.

  1. Kol12 Win User

    Is a standard user account necessary for tight security and home user?


    Is there by any chance you guy's are using Public networks? This could play a big part in what folders are shared by default...
     
    Kol12, Sep 28, 2016
    #61
  2. simrick Win User

    The built-in hidden administrator account is an admin-level account and can not be changed.
     
    simrick, Sep 28, 2016
    #62
  3. simrick Win User
    I am not using a public network, nor a homegroup of any kind.

    I had a chance to test the windows repair program on Tweaking.com yesterday, and it has an option to reset permissions to default. If you would like to try it, let me know. But I would remove all homegroup/network sharing before doing it, so you can start fresh.
     
    simrick, Sep 28, 2016
    #63
  4. Kol12 Win User

    Is a standard user account necessary for tight security and home user?

    Hi Simrick,

    Thanks for your offer. I've got a very helpful guy over at superuser.com helping me to reset the permissions so we'll see how that goes first...

    Basically the Users folder should not have been shared and the individual user accounts should not have inherited full control. Why it ended up like this I'm not sure yet.

    I'd still be interested to know more about your program...
     
    Kol12, Sep 29, 2016
    #64
  5. Kol12 Win User
    Hi Simrick,

    I'd like to try the program you have. Unfortunately it's become to complex to workout with back and forth comments over the forum.
     
    Kol12, Sep 29, 2016
    #65
  6. Kol12 Win User
    I think this has been my issue all along. Being new to multiple accounts I must have granted one time access to to the administrators user folder from my newly created standard account and not thought anything of it. I've then totally overlooked what you guys were saying about the ONE TIME ACCESS still thinking that I shouldn't be able to access the admins user folder from my standard user account!

    I'm so sorry, I've probably really confused you guys!

    I've run @fdegrove's acl.bat again in the hope that it has restored any wrong changes that I've made along the way. Should you know if the acl.bat has been successful once you've run it?

    On a side note, why does access to administrator locked folders/files only need a one time permission to access?
     
    Kol12, Sep 29, 2016
    #66
  7. lx07 Win User
    It doesn't matter if your user is part of the Administrator group or not (as long as you don't mess with UAC).

    In both cases you will by default start processes as a standard user. The difference is that if you are part of the Administrators group you can override the prompt "Do you want this app to make changes to your device". If you are not then you have to enter the password from an administrator. That is all.

    The end result is the same - the launched process will have Administrator privileges and can do what it wants. It has been this way since Vista. You can check this by looking in the details tab in task manager if you right click and add the elevated column - here are 2 command prompt windows - one running as Administrator permissions (I accepted the prompt) and one not.


    Is a standard user account necessary for tight security and home user? [​IMG]


    Do whichever you find more convenient but just don't (in either case) just say "OK" if you aren't sure what the program is or you don't trust it. Except for installation most program should not require Administrator privileges unless they are utilities looking into the whole system not just your data. If a program asks you for this permission you should question why they do and (by default) say no unless you are sure.

    In regards to your question "Why do you only have to do it once" about accessing folders that is because after you have given it authority to do so your user is granted permanent authority to the folder. The one time task has been done and you now have permanent authority.

    It tells you this at the time...


    Is a standard user account necessary for tight security and home user? [​IMG]


    Personally my profile is set as local admin and there is not (afaik) any risk from doing this.

    Other users on my PC I set as standard users as I don't trust them not to just click "OK" on everything.
     
  8. Kol12 Win User

    Is a standard user account necessary for tight security and home user?

    After granting permanent access let's say you wanted to make it inaccessible again how would you do that?
     
    Kol12, Oct 1, 2016
    #68
  9. Bree New Member
    In File Explorer, right-click on the folder and select Properties. On the Security tab you will see your user account is listed as having full control. Click the Edit button, select your user account in the list. DO NOT TOUCH any of the other names. Click Remove, then Apply (or OK).

    You will see a message window saying it is applying changes - then immediately an error message saying (basically) you can't see what you're doing because access is denied (well, it would be, wouldn't it - you've just denied yourself access). Despite the apparent errors, you have successfully removed your access to the folder (until next time you click on it and are asked if you want permanent access).
     
  10. Kol12 Win User
    I thought it might have been something along the lines of this except instead of removing the user I thought you might have to limit their permissions. I tried it myself and limited the user from full control to only read & execute, list and read permissions but that didn't work. It makes sense to remove the user though...

    While doing this I received an error similar to what you describe, a "failed to enumerate objects in the container. Access is denied." It seemed to be for multiple files and folders. I edited these permissions as administrator and they were for a standard account.
     
    Kol12, Oct 1, 2016
    #70
  11. Bree New Member
    Remove the user is the correct action. You can look at the permissions of a folder to which you don't have access by looking at the Properties/Security tab, clicking Advanced then 'Click Continue to attempt the operation with Administrator privileges'. You user account will not be listed. After trying to open the folder and clicking '...Continue to permanently get access to this folder' the only change is that your user account has been added to the list.
     
  12. Kol12 Win User
    Thanks for providing that information. What other folders would a standard user usually not have access to? I seem to be able to browse around most of the OS in my standard account...

    I had a brief issue the other day when logging into the administrator account. It was almost stuck on loading when logging in and took a long time to open up to the desktop. When it did open I was greeted with an error similar to the one we've mentioned and it was something to do with access denied to the desktop. The background was black, there were no desktop icons and the start menu didn't work. I kinda started panicking as I didn't know what had happened and I couldn't recall making any changes anywhere. Another error then popped up very breifly that I didn't have time to capture. I then either restarted or shutdown and the account returned to normal.

    Does this sound like something to be concerned about?

    What stands out in Event viewer after this happened is this:

    "Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.


    Details:
    AddLegacyDriverFiles: Unable to back up image of binary Microsoft Link-Layer Discovery Protocol.


    System Error:
    Access is denied."

    Source: CAPI2

    Event ID: 513
     
    Kol12, Apr 5, 2018
    #72
Thema:

Is a standard user account necessary for tight security and home user?

Loading...
  1. Is a standard user account necessary for tight security and home user? - Similar Threads - standard user account

  2. Administer / Standard User Accounts

    in Windows 10 Customization
    Administer / Standard User Accounts: I want to set up my Microsoft Account with both an Administrator account for making changes and a Standard User account for everyday use. However, I only have one email address. How can I do this? Or must I run as an administrator all the time?...
  3. secure file from standard user

    in AntiVirus, Firewalls and System Security
    secure file from standard user: We have a windows application which is written by electron and SQLite as database, the problem is we want our database file to be secure from deleting or modifying by user , and only application itself can modify that , what are the options here ? is it possible to give admin...
  4. Urgent - Standard User Security issue

    in AntiVirus, Firewalls and System Security
    Urgent - Standard User Security issue: Let me explain... This is a medical facility and we have 10 computers for the adolescent patients to do school work. I just reinstalled each computer from scratch to install windows 10 pro. i put all their programs and security we use to monitor them because they like to...
  5. standard user

    in Windows 10 Customization
    standard user: see attachments. when i view my account settings i see that i'm an administrator, but when use control panel/user accounts/change your account type, it seems to think i am already a standard user. the way UAC acts, it seems to think i am an administrator. which is...
  6. Family linked user account - Standard

    in User Accounts and Family Safety
    Family linked user account - Standard: I 'blocked' my sons' account temporarily. Attempting to bring it back, through Family settings, it shows as 'can sign in', allowed, however, his login option does not appear when trying to switch users. I have rebooted the system as well. I found a suggestion for an mmc...
  7. Changing Standard user account to Administrator account

    in AntiVirus, Firewalls and System Security
    Changing Standard user account to Administrator account: Split from this thread. how do I change administrator on this ProBook s series. administrator passed away gave this laptop to me but cannot change from owner guest to administrator? ***Original title: How do I change administrator on this laptop?***...
  8. About accounts: Admin/Standard user?

    in User Accounts and Family Safety
    About accounts: Admin/Standard user?: I just did a clean install of W10 for a friend. I havent set up a fresh install of 10 and am familar with the structure of accounts in W7> So. Clarify for me the "rights" of accounts(that i set up) in W10 Do they have adminstrator rights? Plan was to set up and Admin account...
  9. standard user account and drive formatting

    in User Accounts and Family Safety
    standard user account and drive formatting: In Windows 10 Pro is there a way to prevent a user without administrator privileges using a standard account from being able to format a usb drive? "Perform volume maintenance tasks" is set for Administrators (Group Policy), which must be the default, but that does not...
  10. Standard Local user Account issue

    in User Accounts and Family Safety
    Standard Local user Account issue: Since upgrading within Windows 10, I've since noticed that I am unable to access my additional user accounts. My main account is fine and have no issue. When I go to log in to additional user account, i click sign in (no password set up for either of my additional...