WINDOWS By Lincoln Spector You’ve probably been told to have both a standard Windows account for safety’s sake and an administrator account because Wi
[See the full post at: Working outside an admin account: Safe but annoying]
![]() |
Patch reliability is unclear. Unless you have an immediate, pressing need to install a specific patch, don't do it. |
SIGN IN | Not a member? | REGISTER | PLUS MEMBERSHIP |
-
Working outside an admin account: Safe but annoying
Home » Forums » Newsletter and Homepage topics » Working outside an admin account: Safe but annoying
- This topic has 29 replies, 20 voices, and was last updated 5 years, 5 months ago.
AuthorTopicTracey Capen
AskWoody MVPNovember 18, 2019 at 1:00 am #2007077Viewing 17 reply threadsAuthorReplies-
OscarCP
MemberNovember 18, 2019 at 2:00 am #2007114Tracey Caper: “But let’s face it, most of us have ignored this advice because … well, juggling two accounts isn’t much fun. ”
I completely agree. Same attitude here. If the price of complete safety is to get tied into knots, then give me risk, give me danger, so I can do my job and still have some time left to go out and get something of a life. (Exaggerating just a little here, not a lot, to make a point.)
Ex-Windows user (Win. 98, XP, 7); since mid-2017 using also macOS. Presently on Monterey 12.15 & sometimes running also Linux (Mint).
MacBook Pro circa mid-2015, 15" display, with 16GB 1600 GHz DDR3 RAM, 1 TB SSD, a Haswell architecture Intel CPU with 4 Cores and 8 Threads model i7-4870HQ @ 2.50GHz.
Intel Iris Pro GPU with Built-in Bus, VRAM 1.5 GB, Display 2880 x 1800 Retina, 24-Bit color.
macOS Monterey; browsers: Waterfox "Current", Vivaldi and (now and then) Chrome; security apps. Intego AV -
gtd12345
AskWoody PlusNovember 18, 2019 at 7:31 am #2007263I have used standard accounts for most of my Windows computing for years, and it has hardly ever been annoying. The only times I really needed to get into my Admin account was to install new or updated software, which I do rarely.
Also, since my new laptop has a fingerprint reader, logging in to Admin is practically trivial; I set Windows Hello up so that my right finger opens the Standard account I use 99% of the time; my left finger opens my Admin account. The left finger also works when I am logged in as Standard, and get a dialogue box requiring Admin credentials to do an install or update.
I think the minor inconvenience (not annoyance) is worth it to give me another layer of protection from ransomeware, etc.
1 user thanked author for this post.
-
mn–
AskWoody LoungerNovember 18, 2019 at 8:18 am #2007312I have used standard accounts for most of my Windows computing for years, and it has hardly ever been annoying. The only times I really needed to get into my Admin account was to install new or updated software, which I do rarely.
You may be fortunate in that you haven’t managed to end up with some critical piece of software that insists on extra privileges on every startup or so.
I mean, really, I can sort of understand needing admin rights the first time you attach a weird USB instrument and install drivers, but on EVERY USE of the instrument or its dedicated application … sheesh.
-
wavy
AskWoody Plus
-
-
berniec
AskWoody PlusNovember 18, 2019 at 9:16 am #2007337Thanks for the good article. I’ve been preaching this for a long time.
Let me just say that you should have a little talk with your colleagues here on Ask Woody — even though many of the tweaks and settings they recommend require admin privileges, they *NEVER* tell you that. Obviously, they’re always running as admin [BOO on them] and so don’t notice when they do something that really needs it
-
mn–
AskWoody LoungerNovember 18, 2019 at 10:53 am #2007434One thing that I’m constantly annoyed by, is that Windows approximately never tells you which specific privilege you need.
I mean, I’d like to set up accounts that are elevated just enough to do whatever, but…
And also, my most annoying scenario was kindergarten-level educational software on Windows XP. Copy protection or whatever meant it wouldn’t run as a regular user.
That’s when I gave up on “Home” versions of Windows for home use.
1 user thanked author for this post.
MrJimPhelps
AskWoody MVPNovember 18, 2019 at 11:02 am #2007437I use a non-admin account for normal work in Windows 8.1, and an admin account when needed. It is very easy – whenever admin rights are needed (such as when I am installing a program), I am prompted for my admin password. I type in the admin password and hit OK.
Not only is this very easy, but also I am alerted whenever Windows is trying to perform some privileged task.
Group "L" (Linux Mint)
with Windows 10 running in a remote session on my file serverbbearren
AskWoody MVPNovember 18, 2019 at 12:32 pm #2007483I have never routinely logged on as a member of the Administrators group. Very, very few procedures require that logged-on level, such as running an in-place upgrade. The vast majority only require Admin-level privileges.
For those apps and utilities that require elevated privileges, I edit the shortcut by ticking the box by “Run as administrator”. I have my Admin account setup for PIN, and when UAC pops up, it’s a quick trip to the number pad to launch a program.
For installing apps/programs, I right-click and select Run as administrator, tickle the number pad, and it’s all go from there on out. It’s much less interuption than clicking File > Save as… when I want to save a new file. I dare say that I use that more often than run as administrator.
Always create a fresh drive image before making system changes/Windows updates; you may need to start over!We all have our own reasons for doing the things that we do with our systems; we don't need anyone's approval, and we don't all have to do the same things.We were all once "Average Users".1 user thanked author for this post.
samak
AskWoody Plus-
anonymous
GuestNovember 19, 2019 at 1:01 am #2007767The fact that UAC exists. Microsoft created it to give people running as admin some level of extra protection, because they knew people weren’t running as a limited user.
I don’t do it, because having to type in my password rather than just click a button is inconvenient. It’s one of the things that I was so happy to get away from Linux, where the sudo prompt would always require a password.
It also encourages me to use a less secure password that is easier to type if I actually have to type it all the time. Passwords are better handled by some sort of password manager.
anonymous
GuestNovember 18, 2019 at 1:05 pm #2007376https://makemeadmin.com/ a lifesaver (and timesaver).
OscarCP
MemberNovember 18, 2019 at 2:39 pm #2007556With Windows 7, I use an account with a level of privilege that allows me to right-click and choose “run as an administrator.” I need to do this rather often, to use the command console application, for such things as to start or stop a service, for example when installing patches as Group B, to stop Windows Update from running and blocking my own use of the installer.
I have a separate “Administrator” account I use to create the other accounts, including the one I use regularly and have just described. Also to go to when logging in in Safe Mode.
Ex-Windows user (Win. 98, XP, 7); since mid-2017 using also macOS. Presently on Monterey 12.15 & sometimes running also Linux (Mint).
MacBook Pro circa mid-2015, 15" display, with 16GB 1600 GHz DDR3 RAM, 1 TB SSD, a Haswell architecture Intel CPU with 4 Cores and 8 Threads model i7-4870HQ @ 2.50GHz.
Intel Iris Pro GPU with Built-in Bus, VRAM 1.5 GB, Display 2880 x 1800 Retina, 24-Bit color.
macOS Monterey; browsers: Waterfox "Current", Vivaldi and (now and then) Chrome; security apps. Intego AVpetermat
AskWoody Plus-
b
AskWoody_MVP -
petermat
AskWoody PlusNovember 24, 2019 at 10:49 am #2010367I get as far as step 4 and select ” I don’t have…” and I just get a “Something went wrong” message. Is this because I have a ‘local” account?
Peter
No. Probably because you’re already using a standard user account, not an administrator.
Thanks “b” but that’ s not the case. Anyone any other sugestions?
1 user thanked author for this post.
-
peterb001
AskWoody PlusNovember 18, 2019 at 4:24 pm #2007618I already have this setup as advised by Lincoln. I’m on Win 10 1903. The difficulty I have is running the Windows utilities (especially those that appear on right click to the windows logo bottom left, such as Disk Management) as admin. The right click doesn’t work from this submenu. Does anyone have an easy answer for this? Thanks
zero2dash
AskWoody LoungerNovember 18, 2019 at 4:43 pm #2007627Doing this is very simple, if you allow it to be that way.
I’ve had several jobs where everyone had split accounts, named fairly inconspicuous things (users start with a u, admin accounts start with a) and the digits are all the same except the first letter. Easy peasy lemon squeezy. My current job, we have our account, plus an SA (SysAdmin) account, plus DA (Domain Admin). Again, same digits, other than the finishing letters being added. Very easy.I do not practice this at home, however, as an IT guy. 🙂 I have 1 admin account on every computer (mine), everyone else in the house is a standard user. No complaints with that setup.
Bundaburra
AskWoody LoungerNovember 19, 2019 at 1:32 am #2007819You can login as an Administrator, but run selected programs as an ordinary user, via StripMyRights. It’s an old program, but still works with Windows 10. For example, if you are an Administrator but you want to run Firefox as a normal user, the command line would be similar to
C:\SMR\StripMyRights.exe /L N “C:\Program Files\Mozilla Firefox\Firefox.exe”.
The /L N switch says to run the following program at the Level of a Normal user. Put the command in a batch file, call it (for example) Firefox.bat, then whenever you want to run Firefox, just execute Firefox.bat. Should apply to any other program.
Windows 10 Pro 64 bit 20H2
-
This reply was modified 5 years, 5 months ago by
Bundaburra.
HATech19
AskWoody PlusRetiredGeek
AskWoody_MVPNovember 20, 2019 at 4:27 pm #2008650Hey Y’all,
As one who has ALWAYS run with an Admin level account this thread intrigued me so I thought I’d do a little experimenting, it’s what I do after all … LOL.
I setup a User level account on my test machine and did some testing. Now a great majority of my computer use revolves around programming (PowerShell, Excel & Access VBA, etc.) and tinkering with Windows. Well needless to say I was frustrated by my access level at every turn.
When running PowerShell to get Admin access I had to use the Run As Administrator right-click menu option and then provide the password for my Administrator account. This was of course expected. However, what was not expected was that PowerShell now thought I was the Administrator so when I used standard techniques to return directories it returned those for the Administrator not for the User. When I tried to run a program to create a Scheduled Task it created it in the Administrator’s account not the users. You can see where this is going.
Almost all of the tinkering with the registry that I do via PowerShell requires Admin access.
Even getting PowerShell to allow me to run scripts required different settings than with an Admin account.Instead of: Set-ExecutionPolicy RemoteSigned -Force with an Admin account.
It’s: Set-ExecutionPolicy -ExecutionPolicy RemoteSigned -Scope CurrentUser -Force with a User account as that is the only level you have access to.
So it didn’t take to long for me to realize that the way I use my computers the User account is a non-starter.
Don’t get me wrong I have my UAC settings set to:
so I still have a few prompts to click. I do get around that by setting up a lot of Scheduled Tasks with shortcuts to run them that run with administrator access, thus avoiding those prompts for stuff I use all the time. Unfortunately, there was no way I could find to set those up in the User account.As always just my 2 cents and YMMV! 😎
1 user thanked author for this post.
wavy
AskWoody PlusNovember 20, 2019 at 5:42 pm #2008682Also some useful info
https://www.tenforums.com/tutorials/63827-run-different-user-windows-10-a.html🍻
Just because you don't know where you are going doesn't mean any road will get you there.RetiredGeek
AskWoody_MVPNovember 20, 2019 at 7:29 pm #2008728Wavy,
I get this:
C:\Users\UAxxxxx>%windir%\system32\runas.exe /user:localhost\xxxxx /savcred G:\BEKDocs\NonInstPrograms\SysInternals\Autologon.exe Attempting to start G:\BEKDocs\NonInstPrograms\SysInternals\Autologon.exe as user "localhost\xxxxx" ... RUNAS ERROR: Unable to run - G:\BEKDocs\NonInstPrograms\SysInternals\Autologon.exe 740: The requested operation requires elevation. C:\Users\UAxxxxx>
-
wavy
AskWoody PlusNovember 21, 2019 at 12:34 pm #2009045I do not know why you got that. But maybe missing quotes? and why ‘Autologon.exe’ try another to test. Is user xxxxx an admin. It has been a while since I use this, I like you have been running as admin and trusting to UAC for a while. (maybe back to XP, when I setup my VM I will check, could be a while)
🍻
Just because you don't know where you are going doesn't mean any road will get you there.
ibe98765
AskWoody Plus-
Kirsty
ManagerNovember 20, 2019 at 10:48 pm #2008779It has long been the advice to not run as an Administrator user for day-to day use, such as this advice from 2004:
The #1 reason for running as non-admin is to limit your exposure. When you are an admin, every program you run has unlimited access to your computer. If malicious or other “undesirable” code finds its way to one of those programs, it also gains unlimited access.
In another discussion on AskWoody a couple of years ago, @mrbrian posted this link:
Why UAC is important and how it can protect you
Paul T
AskWoody MVPNovember 21, 2019 at 1:10 am #2008807But here in my environment, a small private school, everyone logs in to their computers with a domain account. So would your advice still apply, and it so, how?
In a domain the “standard” is to have all users as non-admin users. If users want to make changes or install software it needs to go through the IT dept so that a, they know about it and b, they can support it. This is particularly important in a school environment because kids love tweaking.
cheers, Paul
Viewing 17 reply threads -

Plus Membership
Donations from Plus members keep this site going. You can identify the people who support AskWoody by the Plus badge on their avatars.
AskWoody Plus members not only get access to all of the contents of this site -- including Susan Bradley's frequently updated Patch Watch listing -- they also receive weekly AskWoody Plus Newsletters (formerly Windows Secrets Newsletter) and AskWoody Plus Alerts, emails when there are important breaking developments.
Get Plus!
Welcome to our unique respite from the madness.
It's easy to post questions about Windows 11, Windows 10, Win8.1, Win7, Surface, Office, or browse through our Forums. Post anonymously or register for greater privileges. Keep it civil, please: Decorous Lounge rules strictly enforced. Questions? Contact Customer Support.
Search Newsletters
Search Forums
View the Forum
Search for Topics
Recent Topics
-
Where’s the cache today?
by
Up2you2
9 hours, 49 minutes ago -
Ascension says recent data breach affects over 430,000 patients
by
Nibbled To Death By Ducks
2 hours, 35 minutes ago -
Nintendo Switch 2 has a remote killing switch
by
Alex5723
4 hours, 21 minutes ago -
Blocking Search (on task bar) from going to web
by
HenryW
10 hours, 31 minutes ago -
Windows 10: Microsoft 365 Apps will be supported up to Oct. 10 2028
by
Alex5723
1 day, 3 hours ago -
Add or Remove “Ask Copilot” Context Menu in Windows 11 and 10
by
Alex5723
1 day, 3 hours ago -
regarding april update and may update
by
heybengbeng
1 day, 4 hours ago -
MS Passkey
by
pmruzicka
6 hours, 36 minutes ago -
Can’t make Opera my default browser
by
bmeacham
1 day, 12 hours ago -
*Some settings are managed by your organization
by
rlowe44
23 hours, 3 minutes ago -
Formatting of “Forward”ed e-mails
by
Scott Mills
1 day, 11 hours ago -
SmartSwitch PC Updates will only be supported through the MS Store Going Forward
by
PL1
2 days, 6 hours ago -
CISA warns of hackers targeting critical oil infrastructure
by
Nibbled To Death By Ducks
2 days, 15 hours ago -
AI slop
by
Susan Bradley
9 hours, 51 minutes ago -
Chrome : Using AI with Enhanced Protection mode
by
Alex5723
2 days, 17 hours ago -
Two blank icons
by
CR2
1 hour, 24 minutes ago -
Documents, Pictures, Desktop on OneDrive in Windows 11
by
ThePhoenix
3 hours, 21 minutes ago -
End of 10
by
Alex5723
3 days, 4 hours ago -
Single account cannot access printer’s automatic duplex functionality
by
Bruce
2 days, 2 hours ago -
test post
by
gtd12345
3 days, 10 hours ago -
Privacy and the Real ID
by
Susan Bradley
3 days ago -
MS-DEFCON 2: Deferring that upgrade
by
Susan Bradley
1 day, 3 hours ago -
Cant log on to oldergeeks.Com
by
WSJonharnew
3 days, 15 hours ago -
Upgrading from Win 10
by
WSjcgc50
2 days, 2 hours ago -
USB webcam / microphone missing after KB5050009 update
by
WSlloydkuhnle
2 days, 6 hours ago -
TeleMessage, a modified Signal clone used by US government has been hacked
by
Alex5723
4 days, 6 hours ago -
The story of Windows Longhorn
by
Cybertooth
3 days, 18 hours ago -
Red x next to folder on OneDrive iPadOS
by
dmt_3904
4 days, 8 hours ago -
Are manuals extinct?
by
Susan Bradley
1 day, 9 hours ago -
Canonical ditching Sudo for Rust Sudo -rs starting with Ubuntu
by
Alex5723
4 days, 17 hours ago
Recent blog posts
Key Links
Want to Advertise in the free newsletter? How about a gift subscription in honor of a birthday? Send an email to sb@askwoody.com to ask how.
Mastodon profile for DefConPatch
Mastodon profile for AskWoody
Home • About • FAQ • Posts & Privacy • Forums • My Account
Register • Free Newsletter • Plus Membership • Gift Certificates • MS-DEFCON Alerts
Copyright ©2004-2025 by AskWoody Tech LLC. All Rights Reserved.