Helping people with computers... one answer at a time.

Limited User Accounts in Windows restrict the ability of malware to cause problems on your system. Unfortunately, it may also limit your ability as well.

How effective is using a limited user account to surf the net? I've read that if you get infected with a virus/trojan etc,the amount of damage caused can be dramatically reduced if you were logged on with a limited account. Also if I set up such an extra account (for surfing), do you have run anti virus updates, and do scans on both the administrator and limited account, or does an ONE anti virus/anti spyware scan cover all the accounts on the computer.

In a word, yes - Limited User Accounts are very effective at reducing the potential impact of a virus or spyware.

Unfortunately my experience has been that they're also effective at reducing your abilities in other areas as well.

I'll be honest ... every time I've attempted to set up a Limited User Account (often referred to as LUA), I've been frustrated, and eventually ended up reverting that account to full administrative privileges.

My frustration is not with LUA itself, per se, but with other software.

The concept behind LUA is simple: you don't need every privilege on your machine in order to do most day-to-day activities. Surfing the web, sending email, writing documents or balancing your checkbook do not, and should not, require anything other than the most basic of permissions on the computer.

Taking away certain types of permissions - such as the ability to write to certain system directories, install activex controls and the like - means that it's more difficult for malware to do those things if you happen to run across it as a Limited User. Since so much malware relies on exactly those types of operations, it's actually a very effective strategy.

And yes, even though I have my own frustrations with it, I do recommend it, if possible, as a very valid step towards increasing the overall security of your system. I particularly like the idea of families setting up their children's accounts on a shared computer with LUA.

To do so, by the way, in Control Panel, User Accounts, click on the account you wish to change, click on Change My Account Type, and then select Limited. Note that you will not be able to change the primary Administrator account, and that not surprisingly, you need administrative privileges to actually do this to any account.

"...I do recommend it, if possible, as a very valid step towards increasing the overall security of your system."

Now, about my frustration.

Every time I try to run as an LUA, I keep running into things that I can't do. Things that I want to do. For example installing software in general is an issue using an LUA. If that software expects to be installed for the current user, then logging in as the administrator to install it may still not set up the software for use in another Limited account on the same machine.

Now, to be fair, there are often workarounds. One could temporarily elevate the Limited account to administrator just long enough to install whatever software needs installing. But there are also frequently still complications, and it's certainly an additional, somewhat cumbersome step to what's typically already a complicated process.

Now I definitely understand that there is a fundamental conflict here - you want to prevent installation of malware, while allowing the installation of trusted applications. Unfortunately there's no easy way to distinguish, so LUAs must prohibit both - or at least those that affect protected system areas.

The more fundamental problem is that while many applications do need it, too many assume administrative privileges when they don't. As a result, they fail when installed or run from LUAa.

If there's good news in all this, it's the answer to your other question about anti-spyware and anti-virus software. Most of these applications are installed at the system level, and as such work on the entire machine, regardless of what user you happen to be logged in as, or even whether you're logged in at all.

So, yes, I'm one of those folks who apparently needs to use software that requires or assumes administrative privileges often enough that running as an LUA is simply not a practical option for me. My advice to you: try it. I know I'm an edge case - I do a lot of things that more normal people don't. You may find that all your needs are met in an LUA, and as a result, you will definitely be safer.

Article C2846 - November 20, 2006

Leo Leo A. Notenboom has been playing with computers since he was required to take a programming class in 1976. An 18 year career as a programmer at Microsoft soon followed. After "retiring" in 2001, Leo started Ask Leo! in 2003 as a place for answers to common computer and technical questions. More about Leo.

Not what you needed?

Recent Comments
12 Comments

I have setup my system exactly as described and since I don't use games (which are the ones that are most fiddly about permission rights) everything works fine without hickups or hassles. Admin accounts is ONLY for installation of new programs.

I DO wonder how protected I am with this scheme. Knowing a little about how permissions work with NTFS, I can't figure how a virus could bypass this. Of course there is a way because enterprises get viruses just as anybody else (albeit not as often) and in a corporate environment LUA is exactly the norm. So how do viruses do it? If they can't get write access to the registry, how do they make themselves executable on system restarts?

Posted by: Alex at November 26, 2007 5:27 AM

I can't change the security settings from medium to medium high. Is this normal in a limited user account? and when I change try to change these settings I always get "explorer.exe is not responding" or smoething like that when I close or apply the setting. Is something wrong with Windows in my PC?

Posted by: Adrian Ho at April 11, 2009 6:23 PM

I use all three levels of XP accounts
Admin for Updates, installs, and SW that requires Admin priv.
Limited for regular day to day stuff and some of the SW can be run with "Run As Admin account" such as FTP Voyager
Guest, I setup the Guest account log into it once and then use the Run As to access the "Guest Account" web browser,
but, I've recently bumped up against a problem with the Guest account User Profile not being retained and can't seem to find a solution anywhere except "it's supposed to do that..." but I know it works as I have set up the Guest account to use for web browsing on 4 previous machines 2 with XP Pro and 2 with XP home and the settings are retained in the Guest Profile, I have tried to setup another XP Pro machine and at every log off the profile is deleted which is not good because all Firefox browser add-ons & settings / customizations etc. are also removed the method I use (because I have software that requires I always be logged in as Admin. to use it), is to setup the Guest account and log into it once then "net user Guest 'password'" and then change the browser shortcut in my admin account to "Run with different credentials" and use the "Guest browser" from within the Admin. & or Limited account is there some registry entry or group policy setting that's preventing the Guest profile from being retained?

Posted by: richard at June 30, 2009 4:13 PM

I find my LUA such a pain: example: I downloaded a new font. However, I can only use that new font if I am using Word while logged in as the administrator. I couldn't install the new font while logged in as the LU so had to log in as administrator. I can't figure out how to either allow LU to get full rights to Fonts folder or copy Fonts folder and tell Word where to find it. ARGH! Any ideas?

Posted by: Susan at November 10, 2009 8:02 PM

I have XP Home. I haven't been able to grant myself administrative privileges on the guest account. Apparently it's not a part of the Home version. When in Guest there is no AOL client, that is there is no way to reach the internet. You can't download the client without the admin privileges. Then I tried moving the AOL folder from the C:\ drive to the "shared" folder. This didn't work either. So I gave up and surf the net via the owner's administrative account. Frustrated.

Posted by: duane at September 13, 2010 4:24 PM
Post a comment on "Are Limited User Accounts effective?":





Remember Me?

(You may use HTML tags for style)

Before commenting, please...

  • READ THE ARTICLE. A comment that shows you didn't will be deleted and ignored.

  • Comment only on the article. Use the search box at the top of the page if you have a question about something else.

  • NO PERSONAL INFORMATION in the comment. No email addresses. No phone numbers. No physical addresses.

  • Anything that looks the least bit like spam will be deleted. Links to unrelated sites or links that appear to be primarily promotional will be deleted, or the comment will be deleted.

  • Don't ask me to recover lost passwords or hacked accounts. I can't. Those comments will be deleted.

  • I can't respond to every comment. And I can't vouch for the accuracy of others who do.

Please wait. Your comment is being processed ...