Applying the Principle of Least Privilege to User Accounts on Windows XP
This 100-level technical white paper provides information on the principle of least privilege and describes how to apply it to user accounts on Windows XP. The paper covers the following topics:
Risks associated with administrative privileges
Definition of the principle of least privilege
Definition of the least-privileged user account (LUA) approach
Benefits of the LUA approach
Risk, security, usability, and cost tradeoffs
Implementing the LUA approach
Future developments
This paper also describes at a high-level the issues that affect implementation of the LUA approach and provides useful links to other online resources that explain these concepts in more detail.