A local standard user account for daily work limits what malware and mistaken installs can change: administrators approve elevation via User Account Control, while browsing and documents happen without standing admin rights. Create a separate local (or Microsoft) standard account, keep one admin account for installs only, and sign into the standard profile each day. This how-to is about least-privilege daily accounts—not Controlled Folder Access, not SmartScreen, and not protection history.

1. Why a standard daily account

Running all day as Administrator means every drive-by installer and malicious macro inherits high privilege. A standard user still uses Edge, Office, and Steam normally; when an installer needs elevation, Windows prompts for an admin password—giving you a pause to cancel surprise prompts.

If every family member is an Administrator “for convenience,” one malicious attachment can change system-wide settings. Give teens and less technical relatives standard accounts; keep the admin password separate and unguessable.

2. Account roles at a glance

AccountUse forAvoid
Standard (daily)Email, browser, documents, most appsTurning UAC off to “save time”
Administrator (rare)OS updates that need elevation, drivers, new installsWeb browsing all day while signed in as admin
Guest (if enabled)Truly temporary kiosk-like useLong-term personal email on Guest

3. Steps: create a local standard user for daily use

  1. Sign in with an existing Administrator account.
  2. Open Settings → Accounts → Other users (Windows 11) or Family & other users (wording varies).
  3. Select Add account / Add someone else to this PC.
  4. Choose I don’t have this person’s sign-in information, then Add a user without a Microsoft account if you want a local account (or add a Microsoft account if you prefer sync—still set type to standard).
  5. Create username and a strong unique password; store it in your password manager.
  6. After the user appears, select the account → Change account type → set to Standard User (not Administrator). Confirm your only other account remains Administrator for emergencies.
  7. Sign out. Sign into the new standard account. Move shortcuts you need; do not copy the entire old profile blindly.
  8. Install software only when needed: stay in the standard session until UAC asks, then enter the admin password—or sign into admin briefly, install, and return. Keep Defender or one trusted suite such as Norton or Bitdefender active. Avoid stacking full suites. TotalAV, McAfee, and Avast are other on-site comparison options.

4. If UAC prompts constantly

  1. Note which app requests elevation; update or reinstall from the vendor.
  2. Do not disable UAC.
  3. If a malicious-looking prompt appears after a download you did not start, select No and review Protection history.
  4. Keep CFA and SmartScreen on as extra layers for the standard user session.

FAQ

Is a Microsoft account required?

No. A local standard account works. Microsoft accounts add sync and recovery options—still keep the daily account non-admin.

How is this different from Controlled Folder Access?

Standard users limit privilege. CFA limits which apps can change protected folders. Use both.

Can standard users turn on memory integrity?

Changing core isolation usually needs administrator approval. Configure it from the admin account, then return to daily standard use.

What about work PCs joined to a domain?

Follow IT policy; they may already enforce standard users via directory accounts.

Avoiding how to create a Windows local standard user for daily use does not require paid antivirus. Careful habits and official support paths are a valid buy-nothing stack. If you want multi-device paid protection later, use only these on-site paid links: TotalAV (paid link), Norton (paid link), Bitdefender (paid link), McAfee (paid link), Avast (paid link).