Windows IT Pro is the leading independent community for IT professionals deploying Microsoft Windows server and client applications and technologies.
  
  
  Advanced Search 


June 23, 2004

Oh the Pain: Paul's First Week as a Limited User

RSS
Subscribe to Windows IT Pro | See More Passwords Articles Here | Reprints | Or get the Monthly Online Pass—only $5.95 a month!

Last week, I mentioned that I'd be testing the experience of running Windows XP Professional Edition as a Limited account user, rather than using the more typical Administrator account that XP sets up for you by default. I didn't expect to have anything significant to report this soon, but after a week of experimenting, I have a lot to discuss, both good and bad. Here's how it's going so far.

To test the Limited account scenario, I wiped out my main desktop machine and reinstalled XP from scratch. During installation, XP doesn't offer you a chance to create Limited accounts (as Linux does) but instead creates any account as an Administrator account with no password, which is incredibly unsafe. I created a local "Paul" account during setup and installed XP Service Pack 2 (SP2) after the final reboot. Then, I changed Paul to a Limited account, assigned a password, held my breath, and dived right in. First step: Install a bunch of software.

The software I use is typical in many ways. I generally start with Microsoft Office 2003, which is, of course, savvy to the different types of user accounts Windows users might have and automatically opens a Run As dialog box that warns you that the suite must be installed by an Administrator account. The warning and automatic Run As dialog box is a nice feature, and over the course of installing several software packages, I was surprised by how many programs offered this facility.

However, quite a few software applications aren't aware of this Administrative account requirement, and their setup routines fail with a warning stating that the current user doesn't have sufficient privileges. In such cases, you can generally locate the setup.exe (or similar) application, hold down the Shift key, right-click, and choose Run As. You can then usually install the application under the privilege level of an administrator-type account.

A third level of applications seems fairly insidious. You install these applications by using Run As, and after Setup finishes, the Start Menu contains no shortcut to the application you just installed. So, you have to manually hunt down the application and create shortcuts. (OpenOffice.org and MSN 9 both showed this behavior.) That's silly.

Finally, some applications won't work even after you install them from an administrator-level account. Many games behave this way. For example, after I used Run As to install Activision's "Call of Duty," I couldn't successfully run the game because the first time the program attempted to write a configuration setting, it crashed. When I tried to run the game with Run As, it also failed. I even tried to install the application to a nonprotected folder, with no success.

I'll grant you that games aren't a common application at most businesses, but let's face reality here: We use Windows at work, and we use it at home, and arguably, many people would be more inclined to create Limited accounts for family members than for coworkers. But the home-oriented scenarios are the ones in which the Limited user accounts fall apart most easily.

Another shortcoming is shortcut creation. As I mentioned earlier, some applications don't create a shortcut when you use Run As from a Limited account to install the application. But many applications create shortcut icons on the desktop, which is precisely where I don't want them. And then, you can't delete them from a Limited account. Why, you ask? Well, because the shortcuts aren't stored on your desktop, they're stored in the All Users account's desktop, which transparently copies its contents to the current user's desktop at runtime. To delete these shortcuts, you need to use Run As to run cmd.exe, navigate to the All Users desktop folder (C:\Documents and Settings\All Users\Desktop), then delete them by using the DEL command you might remember from your DOS days. This task isn't one that many home users would know about or be comfortable performing.

A related problem is the Start Menu, which quickly fills up with shortcuts created in both your account and the All Users account. I generally like to subdivide the clutter in the Start Menu with logical subfolders such as Digital Media, Internet, and Utilities so that I don't have to look at too many folders every time I open the Start Menu. But with a Limited account, I find it more difficult to push folders into my structure because most of the folders exist in All Users and the system complains when I try to move them. I would need to log on as an Administrator account to perform this task.

For some tasks, however, XP is surprisingly accessible from a Limited account. After I assigned a password to my Limited account, I could easily access my network shares, where I keep data and application installations. Many applications work fine with no prodding. You quickly learn when you need to use Run As (with many Control Panel applets) and when you don't, although I think a system such as the one that Linux and Mac OS X use--one that automatically prompts you for an Administrator-level password when needed--would be simpler and more secure than XP's haphazard approach.

On Thursday, I'm flying to Chicago to speak to a user group, and I'm still debating whether I should convert my laptop to a Limited account to see how it fares on the road. But so far, the Limited account experience has been painful. At home, I'll continue this experiment to determine in which areas XP falls short. But clearly, some work needs to be done, primarily with third-party software writers, to make Limited accounts a more viable option for most users. I'm a fairly sophisticated user, but I think the average person would give up computers all together before trying to use them like this.

End of Article



Reader Comments
I received my current dell 8200 on jan. 15, 2002 and I had many problems trying to figure out how to use the limited account for Windows XP Pro. When I typed in my user name and password for my verizon dsl connection and email accounts, I had to keep retyping the password everytime I connected to either. The setting just wouldn't stick even after checking the save box. I also use ping plotter and everytime I closed out the program I received a dialog box stated that pingplotter.ini could not be written to. I gave up on using limited accounts for the next year and a half even while going online. but eventually I figured out how to make limited accounts work properly. I created two admin accounts robertadmin and robertlimit. robertlimit is my primary account for all activities. I installed all software under this account. After installation run the software and close it with admin priviledges at least twice to make sure everything is working, i.e. settings stick, no write error messages. I only connect to the Internet, with firewall on, to test new software and activate any programs. Then when I know everthing is working I go back to robertadmin account and lower robertlimit account to limited priviledges. When I use Windows and Office Update I click the Start button then highlight all programs then I right click Windows Update and click Run as... and then I left click the following user and run under the robertadmin account. Robertadmin just exists because windows requires that there be at least one admin account at all times and I use it to raise and lower the robertlimit account from admin priviledges to limited priviledges and vice versa to install any software. I realize this is problematic if you have more than just two user accounts, but I have found this procedure to work well for me.

robert June 23, 2004


About your problem with office shortcuts. I wonder if the "help->detect and repair" in any of the office programs. It normally restores your office shortcuts. I wonder if this may fix your problem and put the shortcuts into your start menu. Of course I've only tried this as administrator.

Mark Chandler June 24, 2004


Is a limited user a member of power users? That's how I set up my personal account under Win2K.

The problem with some installs is not that they don't create Menu short cuts, but that they are put in \D&S\Administrator. You have to move it to \D&S\All Users and fix permissions.

Eric Gisin June 24, 2004


Try using the application compatibility wizard. It works great. It is a intimadating at first, but run the administrator program and create a new fix, find the exe previously installed run in lua, test it and apply the fix. Kazam. Add as many fixes as needed. 95% of all software will work as a LUA. The wizard redirects files to your profile where you have rights to run whatever you want. Free from microsoft.

jb June 24, 2004


With viruses and trojans running rampant on the net these days, having a limited user account is not something that should be difficult to do. It should be the default way (as with Linux) to prevent important system files from being damaged. I've seen many systems go down because either the user had to much power, made an oopsie, or simply because they contracted a virus that ran as the user and would have not been able to do much had the user had not so much privs.

Billy June 27, 2004


Application certified for Windows XP (Logo program) should not have problems running under a limited user account. Some of the problems you mention are not Windows problems, but rather application that are developed without multiple user accounts in mind. They will have issues with shell objects even in machines with multiple accounts with administratove rights. My point is: the OS feature is nice, needed, exists since XP gold, but still application developers (or testers) do not account for it in their design.

Cheers

Peres July 07, 2004


I am trying to run as a limited user. Mostly it is not a problem - except for the continuous Microsoft Updates which are a pain to check for and manage... especially the newer Background (very Un)intellegent Transfer utility.

Anonymous User November 17, 2004 (Article Rating: )


what if you try installing a program through the limited account but the adminstrator account has a password.How do you install that program without knowing the adminstrator password?

Anonymous User February 26, 2005


You can install OpenOffice.org by running "setup.exe -net" as admin and then run setup again with out the "-net" as your limited user. You can then elect to do a workstation install, which just sets up for that user. Non-standard, but it does work. Not documented as clearly as it might be though.

Anonymous User March 10, 2005 (Article Rating: )


I am not sure one can agree with your scenario of trying to install applications on a limited user account.

Applictions should be installed as an admin and any preconfiguration should be done. This could include updating the firewall to allow a new app. if it requires Internet access (and you deem it necessry to run the app). Open Office as described in the article is designed to be installed by an admin yet smart enough to be operated by a limited user.

We would have a safer Internet if we could run most of our applications with a limited account. If so would be be talking about root kit type threats in Windows for the average user?

I would really like to see software written for the higher risk Internet world that we live in.



Anonymous User April 17, 2005 (Article Rating: )


You must be a registered user or online subscriber to comment on this article. Please log on before posting a comment. Are you a new visitor? Register now




Top Viewed ArticlesView all articles
Confirmed: Battery Life Issues Not Windows 7's Fault

Microsoft on Monday issued a lengthy statement about the recent Windows 7 battery controversy, echoing my assessment from earlier in the day, but backing it up with hard, cold evidence. ...

Battery Life Issues Almost Certainly Not Windows 7's Fault

While Microsoft is still investigating a notebook battery life issue that was supposedly caused by Windows 7, some interesting trends have emerged. ...

Microsoft Warns of Windows Version Expirations

Microsoft warned that this year will see three out-of-date Windows versions slip into retirement. ...


Windows OSs Whitepapers Protecting Microsoft SharePoint

Related Events Deep Dive into Windows Server 2008 R2 presented by John Savill

Windows, Unix, Linux Interoperability

Check out our list of Free Email Newsletters!

Windows OSs eBooks Understanding and Leveraging Code Signing Technologies

A Guide to Windows Certification and Public Keys

SQL Server Administration for Oracle DBAs

Related Windows OSs Resources Introducing Left-Brain.com, the online IT bookstore
Looking for books, CDs, toolkits, eBooks? Prime your mind at Left-Brain.com

Discover Windows IT Pro eLearning Series!
Clear & detailed technical information and helpful how-to's, all in our trademark no-nonsense format


Windows IT Pro Home Register FAQ for Windows WinInfo News
Europe Edition About Us Contact Us/Customer Service Media Kit Affiliates / Licensing  
SQL Server Magazine Office & SharePoint Pro DevProConnections IT Job Hound
Left-Brain.com Technology Resource Directory asp.netPRO ITTV Windows SuperSite 
 
 Windows IT Pro is a Division of Penton Media Inc.
 © 2010 Penton Media, Inc. Terms of Use | Privacy Statement