JSI Tip 8966. DropMyRights freeware allows an adminstrator to launch applications, including a browser and e-mail, with ordinary users privileges.

In Browsing the Web and Reading E-mail Safely as an Administrator, Michael Howard, Microsoft Security Engineering, has the following to say about the DropMyRights application:

"DropMyRights is a very simple application to help users who must run as an administrator run applications in a much-safer context—that of a non-administrator. It does this by taking the current user's token, removing various privileges and SIDs from the token, and then using that token to start another process, such as Internet Explorer or Outlook. This tool works just as well with Mozilla's Firefox, Eudora, or Lotus Notes e-mail."

Hide comments


  • Allowed HTML tags: <em> <strong> <blockquote> <br> <p>

Plain text

  • No HTML tags allowed.
  • Web page addresses and e-mail addresses turn into links automatically.
  • Lines and paragraphs break automatically.