💻/🖥️ Windows 10 - Split Admin & User accounts
TYPE | AUDIENCE | PRIORITY | COMPLEXITY | EFFORT | COST | UPDATED |
---|---|---|---|---|---|---|
Preparation / Conduct | 🏗️ | ⭐ | ⭐⭐⭐ | 🏗️ | 🆓 | 2021-06-17 |
Rationale
By splitting Admin and User accounts, a regular user's privilege can be limited so that only Admin users can change the security settings
Instructions
What you should know
- By splitting Admin and User accounts, users will require the admin password for any activities that are potentially risky (like installing new software). So make sure that the password is available to them, either by identifying the person who can provide it, or sharing it through 🔒 Setup BitWarden for the Organisation - though the latter option requires a paid BitWarden business account.
What you should do
1. Separate Admin / User accounts
First check the types of users that have been created for the device:
- Start menu
- Windows system,
- Control panel
- User accounts
Depending on your current setup, the computer's regular user is either:
- Logged in as Administrators, with no User accounts - Create a new user account with a Passphrase and ask your team member to use that instead of the Admin login.
- Logged in as a User, but DOES NOT have Administrator password - Find the person who has the Admin password as you will need it in the next step. If the password isn't strong, change it to a strong Passphrase.
- Already running as a User, and has Administrator password - They are good to go!
2. Set User Account Control to its most strict setting.
Now to enforce a stronger security settings:
- Start menu,
- Windows system,
- Control panel,
- User accounts,
- User accounts, again
- Change "User Account Control" settings,
- Give Admin permission to proceed,
- Drag the slider all the way to the top,
- Click "OK"
- Give Admin permission to proceed.
Now everybody, including your Admin account, will have to give Admin permission to proceed to be able to change Windows settings.
Sources : WindowsTenForums