Standard vs. Admin User

Am I correct that nobody who owns a Mac runs it under a "Standard" user account?
If so, is this what experienced Mac security people do?
Or is "Standard" user something the unwashed masses like me DON'T do, but should?
The "Standard" user seems locked down with no option to personalize commonly personalized things.
By default, my initial user is a local Admin, and either has permission to do things or can obtain permission by supplying the Admin password when requested.
I'm not seeing that when trying to run as a different user with only  "Standard" user privileges.  That makes me wonder if "Standard" is Mac-speak for "Guest".  But I see that a "Guest" user account could be enabled, so I'm thinking "Standard" might lie somewhere between Guest rights and Admin rights.  Am I correct?

Am I correct that nobody who owns a Mac runs it under a "Standard" user account?
No.
If so, is this what experienced Mac security people do?
If you mean running as a standard user, they should.
The "Standard" user seems locked down with no option to personalize commonly personalized things.
Such as?

Similar Messages

  • How i can change to standard user, an admin user

    Hi,
    How I can change to standard user an admin user, if the check box can not be unchecked.
    I have opened the lock to allow for future changes.
    I have more than one admin user.
    As root user, I can't do it.
    Thanks.

    Hi,
    I have, but looks the same, unable to change.
    I finally decided to create a new standard user and delete this.
    Thanks for the support.

  • Send a Unix command through ARD that will change a OS X admin user to a standard user.

    I would love to send a Unix command through ARD that will change a OS X admin user to a standard user. The only thing I found close is
    sudo dscl . -delete /Groups/admin GroupMembership USERNAME
    which does remove the user from the list of admins, but they are still listed as an admin in the user preference panel, and can still use their account to authenticate for admin privileges.

    I'm not having any problems adding or removing users from the 'admin' group by using the syntax's
    dscl . -delete /Groups/admin GroupMembership ARDusername
    or
    dscl . -append /Groups/admin GroupMembership ARDusername
    What I'm saying is if a user is ticked as an Adminstrator in System Preferences and I run the
    dscl . -delete /Groups/admin GroupMembership ARDusername syntax and remove them from the 'admin' GroupMembership they still have the Administrator box ticked in System Prefs and can administer the machine.
    By the way the '/' doesn't work in the syntax in ARD.
    Thanks

  • Changing Admin user that was created at time of install of OSX to Standard

    I have a Mac with an admin account the one that was created at the time of installing OSX 10.4 and I am trying to change that user to a standard user. I have made another admin and have also another standard user. I evry time I tray to change the admin user and turn off admin rights the box is grayed out.
    What is up with the first user that is created at the time of installing the OS? Is that a user that cannot be changed? How can I change its privileges to standard user?

    I have tested this on a few different Macs. I have found some that I can get the admin right away form the fist Admin the one created at the time of installing the OS. Others I am still puzzled to way I cannot change the fist account to a Standard. In all cases I have 3 accounts 2 admins and one standard. The times that I could change the account I was logged in the standard account.
    Is there a work around to get an admin account to have the same permeations as a standard account when the admin box in users is grayed out?

  • Cannot change admin user to standard user (2 Admin Accounts)

    I have an issue that I would like some help with.  When I purchased my iMac a few years ago, I created one user account and just started using my computer.  I am trying to implement a few Safe Computing practices by creating a new Admin user account and changing my original user account to a Standard user. 
    For some reason, I cannot change either of the accounts to a standard user after I type in the password.  I've logged in as both and tried to change the other user profile to a standard user, but the checkbox is greyed out on both of the Admin User accounts.  
    I can create a new standard user, but I have everyting set the way I like it on my current Admin user account.  It would be much easier to have a new Admin User account and "Downgrade" my original Admin account to a standard user account. 
    Any thoughts on why the option to change from an Admin user to a standard user would be "Greyed Out"?  The support articles walk me through, what should be a few simple steps, but I can not change the settings because the checkbox is greyed out.
    Thanks in advance for any thoughts, suggestions, ideas....

    In a way it makes sense that the original Admin Account can;t be changed. If a user changed that account to non-admin and that was the only admin account it would be  a mess to undo it. I agree that there should be some indication of this and even the ability to over rider  it in a case like yours.
    As there isn't the next best thing will be for you to duplicate the current admin account as a new user account and then use that duplicated account.
    See How to copy a user account for instructions on how to duplicate an account.
    post back if you have any questions.
    regards

  • How 2 synchronize my Bookmarks, not another PC, but between the Admin user and a Standard User, on my same PC?

    Thanks for giving us the Sync function. But, never have I seen any mention of applying this to Sync bokmarks among Windows User Accounts or Mac Profiles. I am running Windows 8 (soon to go to 8.1 Update - - or, maybe, to Windows 7 Professional, if M$ cannot straighten out and fly right with 8.1U) on the HP notebook, and Mac OS X Lion (soon to go up to Mavericks or Yosemite) and I would like to take the good advice and do most of my browsing in the non-admin users instead of the Admins, but ... when I add some Bookmarks in one User, I needto find the new Bookmarks available in the other as soon as I switch Users. Please advise; someone expert in Windows/Firefox, and someone (maybe the same?) for Mac/Firefox. Your helpful assistance will be appreciated.

    Sync works fine between two different Login User Accounts on a PC.And also between different operating systems on the same computer, for users who dual-boot.

  • Non admin user - changes not saved (Safari settings, system prefs, etc.)

    iMac, 2 users, one is administrator and other is standard user. Recently, in the non-admin user account, it has become impossible to make any changes. For example, adding an application to the the Dock, after logging out and back in next time, the application is not in the Dock any more. Also, making changes to the prefs in Safari, changes are not saved.
    I noticed this after installing FireFox v4. I installed it as admin whilst in the non-admin users account. However, I don't believe that the installation of FF has anything to do with the problem, it just highlighted it. I've checked the permissions for the various directories that hold prefs info such as user/libraries/application prefs/etc. etc. and also Safari prefs. Nothing I can see that has changed in system prefs.
    Any ideas on what has caused the problem (kids are known to fiddle from within the non-admin account) and any ideas on how to fix it?
    Thanks

    Hi PPRuNe,
    You could try making the standard user an Admin too. To do this, make sure you are logged in to the standard user, go to System Preferences > Accounts > Standard user (you may have to unlock the padlock) > Allow user to administer this computer
    This will allow changes to be made without being prompted for a password all the time.
    However, if you had Parental Controls on, they probably won't work on an admin account because as an admin you have complete control over a computer, so the computer thinks there is no point in having the controls turned on. And if the kids are known to "fiddle," just think carefully!
    Hope this helps you.
    Chris.

  • Weblogic admin user password change w/o disrupting existing users

    Hi Folks,
    As a business policy we need to change the password of the admin user in weblogic after a cycle of specific period.
    Please let us now how can we do that without losing the other existing users in 'my realm.'
    I understand that we can use the weblogic.utils.security.AdminAcoount utility to give the new password, which will create a new DefaultAuthenticatorInit.ldift file in +<domain-home>/security+ folder (according to Doc ID 1082299.1).
    The password will change but the users in 'my realm' will be lost. (there are many users and it is a production environment so recreation is out-of- question)
    Is there a way we can retain the users and still proceed with the password change?
    Cheers,
    Jeegar

    Hi Jeegar,
    This can be doen by followin the standard procedure by login to console and navigate to :-
    DOMAIN_STRUCTURE--->Security Realm--->myrealm--->Users and Groups---->User tab click on the user weblogic
    --click on the password tab and put the new password there and save (password is changed for the user here)
    ---Logout from the console and login to the console again using the new password
    But when the server starts it do not read the password for the user directly from the realm rather it picked the same from the $DOMAIN_HOME/servers/AdminServer/security/boot.properties
    Now in order to make this change available when the server starts change the values for the username and password in boot.properties and specify them in plain-text and save the same.
    Now next time whenever the server will start it will pick up the new values from the boot.properties and once the same had been accepted those will be encrypted again.
    You might have to make the change for the boot.properties for all the Managed Server if you have the Managed Servers in the domain which will be located at the location $DOMAIN_HOME/servers/<<Managed Server Name>>/data/nodemanager/boot.properties
    You can test the steps on some lower environment first and try the same in Critical environment once the testing goes successful.
    Regards,
    Vijay
    Edited by: V Kumar on Oct 25, 2012 3:06 PM

  • Is there any way to prevent non-admin user accounts to receive software update prompts?

    I am the admin account user on our MacBook Pro, and there is one standard user account on it as well. Generally we are both logged on so we can quickly switch between user accounts and 'spin the desktop'.
    For some reason, all the software update notifications seem to be received when the standard user account is the active one.
    I know that the standard user cannot actually update without my account password and my Apple ID, but a) The notifications confuse the non-admin user, and she gets flustered, and b) Even if she manages to cancel them from the notification area, she then has to remember to tell me verbally that she had had one.
    Is there any way to stop her receiving the update notifications altogether?
    Running OS X 10.8.2 on MacBook Pro.
    Thanks in advance.

    You should be able to do this by unchecking the software update service in the system preferences to prevent the system from running the check as the "_softwareupate" user and passing it to the notification service that broadcasts to all user accounts. Then you can check for the software update in an admin account using the following Terminal line:
    /System/Library/CoreServices/Software Update.app/Contents/Resources/SoftwareUpdateCheck -Check YES
    This line can be scripted via Terminal services to run on a schedule (ie, every few hours), and if there are found updates it will launch the App Store for that account and present them. Granted this approach circumvents the notification service, but should work. To try this, open TextEdit on your computer and in a new document choose "Make Plain Text" from the Format menu.
    Then copy and paste the following text into the new document:
    <?xml version="1.0" encoding="UTF-8"?>
    <!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
    <plist version="1.0">
    <dict>
              <key>Label</key>
              <string>local.softwareupdatecheck</string>
              <key>ProgramArguments</key>
              <array>
                        <string>/System/Library/CoreServices/Software Update.app/Contents/Resources/SoftwareUpdateCheck</string>
                        <string>-Check</string>
                        <string>YES</string>
              </array>
              <key>StartInterval</key>
              <integer>21600</integer>
    </dict>
    </plist>
    When done, save the document to your desktop as "softwareupdatecheck.plist" or anything as long as it ends with ".plist." Then get information on the file in the Finder to ensure its name ends with plist and not anything else like "plist.txt" (rename it accordingly in the Info window's "Name & Extension" section.
    With the file name appropriate, hold the Option key and choose the "Library" option in the Finder's "Go" menu. Then locate the folder called "Launch Agents" in the library and drag the text file to this folder. Then log out and log back into your account.
    This text file is a launch agent script that instructs the system to run the program arguments every 21600 seconds (6 hours) whenever the user is logged in. The program arguments here are simply those to check for software updates for the system. You can change this time interval to be any number of seconds you would like, but there are other options to use besides the "StartInterval" key for scheduling the task. This approach simply has it repeat every number of seconds, but you can use other options to have it only run on specific hours or days, or only have it run once when you log in, etc.
    If this works for you, then if you'd like to explore these other options write back here and we can go over them for you.

  • Migration Assistant created admin user w/ Macintosh HD volume on desktop

    Hi,
    Summary:
    MBP 17" (running Leopard) logic board died
    Retrieved hard drive from MBP and put in USB 2.0 caddy
    Bought Mac Mini 2.5 intel core i5 w/ latest Mountain Lion
    Used for a couple of days as main Administrator user, set up a VPN etc, every working fine.
    Made a back up using Time Machine on a USB connected My Passport Edge for Mac
    Used Migration Assistant to transfer user account from MBP HD (with Leopard) - this was the main adminstrator (not root superuser) of the MBP
    When prompted, renamed the Leopard user account to MacBook so no conflict with new Mountain Lion administrator user
    Transferred everything but applications and download folder of the main (administrator) user on the MBP.
    All appeared successful.
    Restarted Mac Mini and logged into the User account created by Migration Assistant---all files there etc so far so good.
    Then I noticed that this migrated user still had Admintrator rights and appears to have reset some of the global settings effecting the original ML admin user (the one I eventually want to carry on using)
    First inkly of this was that the VPN server I set up was no longer recognised by Safari in any accounts on the machine.
    Logged into original ML administrator user and changed the migrated MBP user to a 'standard' user with no rights to do change settings on the computer.
    [still can't get Safari to recognise the VPN proxy server]
    Decided I'd better make a back-up to the Time Machine on the My Passport, but had to follow these instructions http://pondini.org/TM/A4.html for a 'Full Reset of Time Machine'. Which did the job.
    Then I logged back into the migrated MBP user account to look around. There on the desktop is a volume called 'Macintosh HD' (the same as the main computer default name that is used my Mountain Lion.
    When I do a get info on this volume it tells me the following:
    Kind: Volume
    Created: Friday, 19 October 2012 (which is an odd date)
    Modified: Today ...
    Version 10.8.2
    Formal: Mac OS Extended (Journaled)
    Capacity: 499.25GB
    Available: 361.32GB
    Used .....(127.93 GB on disk)
              Sharing and Permissions
                   You can only read
                   system Read & Write
                   wheel Read only
                   everyone Read only
    Can I delete this volume off the desktop or will that mean I lose all the files and folders for this user? Why is there a 137GB volume on the desktop?
    Also, as it's called Macintosh HD (the same as Mountain Lion's Computer name) isn't this likely to be causing some clashes?
    I will eventually be deleting this migrated user, once I have all the emails, notes, etc off Entourage's Main Identity imported into Outlook 10. In the meantime this volume on the desktop is worrying me.
    My question is: what should I do about this double Macintosh HD volume on the migrated MBP user account?
    Thanks for your help.
    Cheers,
    Tracy

    There are settings in Finder's Preferences to show Hard Disks on the desktop. So, that is likely normal. Deleting it would be bad.

  • Acrobat 9 pro and Admin user/password

    Every time Acrobat 9 pro on my Mac (OSX 10.6.1) is launched it sakes for my admin user/password. If I enter the info in every time I launch Acrobat 9 pro admin it works, but the next time I login with my network user account Acrobat 9 pro want the admin user/password again.  What might be causing Acrobat 9 pro to want admin user/password.

    If, as it it says on top of the page, the question is "possibly answered", the "1 correct answer" is not shown.  The mystery and annoyance remains.
    Acrobat 9 Pro (installed as part of CS4 Design Standard by the same admin user that now wants to use it, OSX 6.7) asks for my password every time I start it:  "Type your password to allow Adobe Acrobat Pro to make changes."  The only necessary change that I see is upgrading back to version 8, which didn't suffer from this bug.
    When I click cancel (twice – the window returns once.), I'm told that "Adobe Acrobat could not install correctly.  An invalid password or user name was entered.  Adobe Acrobat will now quit."
    To repeat it, Acrobat is already installed, and I've entered the username-password combination several times correctly to use the software, but it's not acceptable to do that every time in all eternity.  Please, Adobe, fix this quickly or give solution if one exists.

  • Acrobat 7 requires admin password at every launch for non admin users?

    acrobat 7 requires admin password at every launch for non admin users?
    any one with a solution or similar problem?
    thanks for any help.

    I've been avidly following all of the threads regarding this issue...yet none of the solutions have worked for me. I've got 11 Mac users that do not use the Creative Suite..only Acrobat, Quark, etc. I've tried installing and re-installing through both Admin and User accounts, I've tried the AdobeBib XML change, I've tried enabling Root and installing, changing permission on the Acrobat folder, etc. all to no avail. I still get asked for Admin Authentication every time Acrobat and Distiller are opened (except on the Admin account side). This is happening on one particular Mac (G4, 1GB Ram, OS 10.4.3) for both Acrobat Standard 6 and 7 as well. The biggest issue that also happens in tandem with the Acrobat installs is the inability to print from Quark. I get the following error when printing: "The process "pictwpstops" terminated unexpectedly on signal 6." Because of the necessity to print Quark documents, I have uninstalled all Acrobat on the machines until we can get a fix. This resolves the printing problem with Quark. The only option left is to set up all users as Admin accounts - which I really do not want to do. Any other suggestions out there? I've got more information available if needed.

  • What is the default admin user account login id and password in Windows 8?

    Hi all,
    The current admin acccount in Windows 8 system are changed to Standard and no other Admin account is available in the system.
    What is the default admin user account login id and password in Windows 8?
    Or 
    Is there way to change the User role for the account?
    Please use Marked as Answer if my post solved your problem and use
    Vote As Helpful if a post was useful.

    I am able to login as a Normal user, can not login as administrator.Hence can not install any software or change my user settings or create a new user.
    What is the default admin password. How can i reset it form my user account
    C:\Users\Amit>net user Administrator
    User name                    Administrator
    Full Name
    Comment                      Built-in account for administering the computer/domain
    User's comment
    Country/region code          000 (System Default)
    Account active               No
    Account expires              Never
    Password last set            7/26/2012 12:57:03 PM
    Password expires             Never
    Password changeable          7/26/2012 12:57:03 PM
    Password required            Yes
    User may change password     Yes
    Workstations allowed         All
    Logon script
    User profile
    Home directory
    Last logon                   9/16/2013 1:16:30 PM
    Logon hours allowed          All
    Local Group Memberships      *Administrators
    Global Group memberships     *None
    The command completed successfully.

  • Deny logon to an admin user.

    I have the need to only allow a user elevated access to an administrators account (to unlock system preferences and install software).
    So the user can use their standard account and if required enter other credentials to so simple admin tasks, however I do not want this admin user to be able to login.
    Is there a way to do this?
    Many thanks in advance.

    If anyone else is attempting this have a look at the response to the question on th Amsys forum
    http://forums.amsys.co.uk/forum/viewtopic.php?showtopic=67&lastpost=true#71

  • Admin user can't administer other accounts

    I somehow did something on my iMac when I was playing around with the account settings and I activated parental controls. Even though I am logged on as the admin user, I am not able to administer either the parental control permissions for the guest account or the other standard account on my iMac. When I am in account settings those two other accounts are completely grayed out, as are the + and - so that I can't even add a new account or delete any of the existing ones.
    Does anyone know how to fix this?

    Ah! The missing information. I have a suspicion that your account's reverted to a standard one, thereby disabling your ability to administer things. See http://support.apple.com/kb/TS1278 for starters.

  • Don't know the Admin User!!

    Hi everybody ,,,
    I have a problem which is when I wanna to install a program the computer asks me to type the admin user and password and I don't know both of them .. also my user which I have been using it is a standard user although it's the user which I created it when I used the Mac the first time,,
    so ,,
    could u help me please ,, how could I know the admin user and password or how could I install the programs even with the standard user ?
    and how could I make it Admin,,
    Thanks,, & I'm looking forward to have an answer ..
    Message was edited by: LioN_HeArT

    Excellent! I had the problem of loss of admin rights myself, and was curious if root had also been messed up so went to change his password. I thus discovered what is Apples recommended solution for the vanilla version of the problem. Incidentally there is at the top of the listing for 10.5 topics a little pink tinged section and that contains a slew of Leopard solutions.
    LioN HeArT, two pieces of advice 1)you really ought not to have (if so) your only user be an admin. That would mean that attacks whilst browsing especially could wreak more danmage. Your day to day user should be a non admin. If you care to follow my advice, despite your efforts you should demote the admin user to standard. Do that because if I am right about your scheme most of your user created data will be in that admin and it is a clart to shift the data to a non admin. HOWEVER before you do that follow this second advice
    2) set up two new admins. One you will use for the normal sorts of admin tasks, the other you hold in reserve and just test occasionally.
    By the way I hope you have disabled the root. To leave him enabled is a security risk. The easiest way is in Directory Utility but you can also do it from a single user boot. Root and the admins should have good passwords but I suspect they have judging from your upper/lower case username here.
    Finally, tidy up Apple's website and mark the query as settled, if it is so.

Maybe you are looking for