Hi,

I have windows XP installed on my office computer.

I have created a seperate logon account coz I do not want my colleagues to use my login info to access the computer.


So my question is how do I assign roles to this new user?


I want to disable all admin functions like install a software, create new users etc.

PS:

1) I am using win xp Pro 2002.
2) The Guest account does not work for some reasons.


Thanx

Dani AI

Generated

Building on 's direction, here are practical, low‑risk ways to stop a co‑worker from installing software or seeing the list of installed programs without redoing every shortcut.

  • Use permissions rather than moving every shortcut. From an administrator account, change the security on the shared Start Menu and shared Desktop folders so standard users cannot list/read those folders. Remove inherited read/list permissions for the Users group and leave Administrators with full control. Test immediately by logging in as the restricted account. Do not set broad explicit Deny entries for Administrators and keep a secondary admin account available in case of a lockout.

  • Apply user‑focused Group Policy settings (XP Pro) rather than brute file moves. Useful policy types are those that hide or disable Control Panel applets, remove Add/Remove Programs access, and restrict Start Menu features. Group Policy changes are reversible and apply consistently to anyone in the restricted user set.

  • Prevent installation execution as well as visibility. Software Restriction Policies or execution‑rules (configured via the security policy editor) can block installer file types or prevent binaries from running in user‑writable folders. That stops installation attempts even if a user finds an installer.

Cautions and best practices:

  • Back up the shared Start Menu/Desktop shortcuts before changing permissions.
  • Make and keep at least one alternate administrator account to recover from accidental lockouts.
  • Test every change with the target account before making it permanent.
  • Decide whether the goal is cosmetic (hide entries) or functional (prevent execution). Permissions and policies address different parts of that goal; use both when necessary.

If the specific desired outcome is listed (only hide entries vs. completely prevent installation), a concise step‑by‑step for that exact scenario can be provided.

Recommended Answers

All 3 Replies

Hey Cancer10

The places to be for this administration is "compmgmt.msc" and "secpol.msc". (Both can be run from Start > Run).

In computer manager (compmgmt.msc), you can configure local logins under "Local Users and Groups > Users". Double-click the login you created, and select the "Member-Of" tab. Make sure they are only a member of "users".

By default this restricts their access to install programs, view others profiles, and create new users.

You can further configure permissions for users in security policies (secpol.msc). Permissions are given under "Local Policies" > "Security Rights Assignment". But TBH, making sure the user only has "users" permissions should be sufficient.

The Guest Account on WinXP is disabled by default, and for security, is's best to leave it this way.

Regards, David

ok thanx for your help.

Another question - I have created a new user account from the control panel. How do I make this new account so that they cannot see my Installed programs under Start > All Programs


Thanx

Hey

Browse to "C:\documents and settings\all users\start menu\Programs" and move the icons you want to hide from them to "C:\documents and settings\********\start menu\Programs" - where ******** is your username.

Similarly with in "C:\documents and settings" you'll find each username, or all users folders, and can change Desktop Icons as well.

Regards, Dave

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.