Alert icon Keyboard navigation enabled.
Alert icon TAB or Shift+TAB to navigate across. Down ↓ to open menu. ESC to close menu.
Alert icon Down ↓ to select section. Right → to activate. Up ↑ / Down ↓ / Tab to traverse all. ESC to exit.
BeyondTrust
Skip to content Use space or enter to skip.

What can we help you find today?

Instant Results
  • Website Results
  • Technical Documentation

Filter Options

Focus your search

Filtering by

Your recent searches:

Contact Us Chat with Sales Get Support
  • English
  • Deutsch
  • français
  • español
  • 한국어
  • português
  • Home
  • Resources
  • Blog
  • Removing Privileged Credentials From Windows Users Without Impacting Usability current page
Link copied

Removing Privileged Credentials From Windows Users Without Impacting Usability

Sep 28, 2015
Author:
Russell Smith Bio Pic 2021 Square
Russell Smith
IT Consultant & Security MVP
Blog banner default
Removing Privileged Credentials From Windows Users Without Impacting Usability
Russell Smith Bio Pic 2021 Square
Russell Smith
IT Consultant & Security MVP

multiple computers

Long before the days where Windows NT was merged with the consumer version of Windows, users became accustomed to working with full system access. Before Windows XP was released, the absence of the NTFS filesystem in Windows ME and earlier OSes, meant that access control lists couldn’t be used to secure system resources, so users always had unfettered access to the system.

Even in the corporate world, Windows NT Workstation often required users be given power user or administrator access to run software, as developers rarely adhered to best practices in terms of creating applications that would run under a standard user account. And so the scene was set, that Windows users are always ‘administrators’.

But times have changed, and the Internet has brought with it a different threat landscape that changes almost daily. Not only do security experts now recommend the removal of administrative rights, even from IT staff, but regulatory compliance demands and other security programs, such as the UK government’s Cyber Essentials Scheme, require that administrative privileges be removed from users.

Political and technical challenges of removing administrative privileges

IT has always been reluctant to remove administrative privileges from end users for several reasons. The first that comes to mind, and shouldn’t be overlooked, is the political challenges of such a move. Taking away a perceived privilege can be difficult, much like denying a person their freedom, so a change in IT policy has to be managed carefully to ensure users and management are onboard.

There are still legacy applications that require administrative privileges, and while User Account Control (UAC) in Windows Vista and later OSes increases the number of legacy applications that can run with a standard user account, there are still times where a program may require administrative rights. Additionally, there may be occasions where users legitimately need to carry out system tasks that require administrative privileges, especially on portable devices that have limited connectivity to the Internet or company intranet.

But the risks of administrative privileges in today’s threat landscape greatly outweigh the benefits, and removing administrative privileges from end users and IT staff is critical for ensuring that systems remain secure, and should be part of a defense-in-depth security strategy that includes deploying antimalware detection, endpoint firewalls, and ensuring that operating system and updates for third-party software are installed in a timely manner.

Overcoming the challenges

In this webinar, join me to learn about some strategies that can be used to overcome these challenges. I’ll discuss how the Application Compatibility Toolkit (ACT) and UAC can be used to deploy shims to improve legacy app compatibility with standard user accounts, and how embracing Universal Apps in Windows 10 can enable organizations to secure systems but still allow users to install ‘after work applications’

Author/Presenter: Russell Smith, Windows & IT Security Expert

Latest Posts
  • 14 Password Management Best Practices
    May 28, 2026 14 Password Management Best Practices
    Blog
    12m
  • A Security Researcher’s Guide to Understanding Copilot Studio AI Agents
    May 26, 2026 A Security Researcher’s Guide to Understanding Copilot Studio AI Agents
    Blog
    3m
  • How to Secure Cloud-Native Infrastructure at Scale and Speed: A Conversation with Madhu Adireddi
    May 21, 2026 How to Secure Cloud-Native Infrastructure at Scale and Speed: A Conversation with Madhu Adireddi
    Blog
    5m
  • Cybersecurity as a Boardroom Priority for Major African TelCos
    May 12, 2026 Cybersecurity as a Boardroom Priority for Major African TelCos
    Blog
    8m
  • Geopolitics and Cybersecurity: Why Attackers Go After Identities and Privileged Access First
    May 11, 2026 Geopolitics and Cybersecurity: Why Attackers Go After Identities and Privileged Access First
    Blog
    4m
Related
  • BeyondTrust Named 'Top Innovative Vendor in Secure Identity Solutions’, Recognized for Outstanding Contributions Addressing IT Security in MEA Region
    Oct 10, 2019 BeyondTrust Named 'Top Innovative Vendor in Secure Identity Solutions’, Recognized for Outstanding Contributions Addressing IT Security in MEA Region
    Blog
    1m
  • Google Docs users hit by sophisticated phishing scam
    Oct 20, 2017 Google Docs users hit by sophisticated phishing scam
    Blog
    1m
Share this Article
  • Link
Stay up to Date
Get the latest news, ideas, and tactics from BeyondTrust. You may unsubscribe at any time.

Keep up with BeyondTrust

Customer Support Get Started
  • LinkedIn
  • X
  • Facebook
  • Instagram
  • Add BeyondTrust as a preferred source on Google
  • Privacy
  • Security
  • Manage Cookies
  • Do Not Sell My Data
  • WEEE Compliance

Copyright © 2003 — 2026 BeyondTrust Corporation. All rights reserved. Other trademarks identified on this page are owned by their respective owners. BeyondTrust Corporation is not a chartered bank or trust company, or depository institution. It is not authorized to accept deposits or trust accounts and is not licensed or regulated by any state or federal banking authority.

Prefers reduced motion setting detected. Animations will now be reduced as a result.