Windows security for different user types

Whether this will work perfectly or not, I am not sure. You can also hide the drives from My Computer in the Registry.In summary, the conversation discusses the use of Windows 8.1 and the security tab in the properties of the C drive. The user is wondering if they can delete all groups and users from the security tab and only add their own username. The expert explains that this may cause issues with services running under the SYSTEM user group and recommends creating a standard account for the nephew to restrict access to certain drives. Additionally, the expert suggests hiding the drives from My Computer through the Registry.
  • #1
9
4
I am using Windows 8.1. Right-clicking on my drive C, where I install windows, and choosing properties shows me the security tab. I see some groups and users that have privileges to use the drive. What if I delete all of them and add only my own username in there ? For instance, can I still boot the computer in save mode ? Thank you. :)
 
Computer science news on Phys.org
  • #2
If you for instance remove the SYSTEM user group, services running in the context of SYSTEM (real name is LocalSystem, "SYSTEM" is just a token within the LocalSystem account) may misbehave.

I have no idea if it will boot in safe mode. It should. Just that whatever it is that runs under the token SYSTEM in safe mode, will simply not work or may misbehave.

If you search, you will find in other forums that some have removed this user group and had no problem whatsoever with their system. At least not visible. I'm sure something broke, but they say it was fine.

Sources:
https://msdn.microsoft.com/en-us/library/windows/desktop/ms684190(v=vs.85).aspx
https://msdn.microsoft.com/en-us/library/windows/desktop/aa379624(v=vs.85).aspx
 
Last edited:
  • Like
Likes Lizabella
  • #3
I have an anoying nephew who always messes up all stuff in my computer when I am not at home. I don't want him to access to read or store files into my data drives (D or E). Even though I have a local account set up as an administrator user, usually other accounts with similar privileges can still see and access these 2 drives. I now use bit lockers to encrypt both and also I delete all users except me and System as seen in the security tab.
 
  • #4
I see. In any case you can alternatively try creating a standard account for your nephew. Then, go to one of the drives (say D), right click it and in the Security tab set the permissions for your nephew's account to Read & Execute, List folder contents, and Read. Leave it out of other permissions. Do that with each data drive you don't want your nephew messing around and it should be okay.

At least in theory.
 

Suggested for: Windows security for different user types

Replies
6
Views
1K
Replies
6
Views
1K
Replies
4
Views
1K
Replies
3
Views
1K
Replies
4
Views
1K
Replies
5
Views
879
Replies
14
Views
1K
Replies
8
Views
476
Back
Top