Windows security for different user types

  • Thread starter Thread starter Lizabella
  • Start date Start date
  • Tags Tags
    Security Windows
Click For Summary

Discussion Overview

The discussion revolves around Windows security settings, specifically regarding user permissions on drives in Windows 8.1. Participants explore the implications of modifying security settings, such as removing user groups and setting permissions, particularly in the context of preventing unauthorized access to files and ensuring system functionality.

Discussion Character

  • Technical explanation
  • Debate/contested
  • Conceptual clarification

Main Points Raised

  • One participant questions the consequences of deleting all user groups from the security settings of drive C and adding only their own username, specifically whether this would affect the ability to boot in safe mode.
  • Another participant suggests that removing the SYSTEM user group may lead to misbehavior of services running under that account, although they express uncertainty about safe mode functionality.
  • A different participant shares their experience of using BitLocker to encrypt drives D and E to prevent access by a relative, while also modifying user permissions to restrict access.
  • Another suggestion is made to create a standard account for the relative, setting specific permissions to limit access to certain drives, although it is noted that this is theoretical.

Areas of Agreement / Disagreement

Participants express differing views on the implications of modifying user permissions and the potential effects on system functionality. There is no consensus on the outcomes of removing user groups or the effectiveness of the proposed solutions.

Contextual Notes

Participants acknowledge the uncertainty surrounding the impact of removing the SYSTEM user group and the effectiveness of permission settings, indicating that experiences may vary and that some issues may not be immediately visible.

Who May Find This Useful

This discussion may be useful for users seeking to understand Windows security settings, particularly in relation to user permissions and access control for different user types.

Lizabella
Messages
7
Reaction score
4
I am using Windows 8.1. Right-clicking on my drive C, where I install windows, and choosing properties shows me the security tab. I see some groups and users that have privileges to use the drive. What if I delete all of them and add only my own username in there ? For instance, can I still boot the computer in save mode ? Thank you. :)
 
Computer science news on Phys.org
If you for instance remove the SYSTEM user group, services running in the context of SYSTEM (real name is LocalSystem, "SYSTEM" is just a token within the LocalSystem account) may misbehave.

I have no idea if it will boot in safe mode. It should. Just that whatever it is that runs under the token SYSTEM in safe mode, will simply not work or may misbehave.

If you search, you will find in other forums that some have removed this user group and had no problem whatsoever with their system. At least not visible. I'm sure something broke, but they say it was fine.

Sources:
https://msdn.microsoft.com/en-us/library/windows/desktop/ms684190(v=vs.85).aspx
https://msdn.microsoft.com/en-us/library/windows/desktop/aa379624(v=vs.85).aspx
 
Last edited:
  • Like
Likes   Reactions: Lizabella
I have an anoying nephew who always messes up all stuff in my computer when I am not at home. I don't want him to access to read or store files into my data drives (D or E). Even though I have a local account set up as an administrator user, usually other accounts with similar privileges can still see and access these 2 drives. I now use bit lockers to encrypt both and also I delete all users except me and System as seen in the security tab.
 
I see. In any case you can alternatively try creating a standard account for your nephew. Then, go to one of the drives (say D), right click it and in the Security tab set the permissions for your nephew's account to Read & Execute, List folder contents, and Read. Leave it out of other permissions. Do that with each data drive you don't want your nephew messing around and it should be okay.

At least in theory.
 

Similar threads

  • · Replies 51 ·
2
Replies
51
Views
7K
  • · Replies 6 ·
Replies
6
Views
2K
  • · Replies 13 ·
Replies
13
Views
2K
  • · Replies 18 ·
Replies
18
Views
3K
Replies
12
Views
3K
Replies
4
Views
3K
Replies
2
Views
3K
  • · Replies 7 ·
Replies
7
Views
2K
  • · Replies 2 ·
Replies
2
Views
3K
  • · Replies 11 ·
Replies
11
Views
3K