Passwords are case sensitive and can be up to 14 characters. User names are not case sensitive and can be up to 20 characters. The user's home directory can be specified when the user is created or set later. The home directory is where data from an application is saved by default and where the command prompt will be when a command line session is begun.
| Right | Description | Groups with the Rights |
| Access this computer from the network * | The user can connect to the computer remotely. | Administrators, Power Users, Everyone |
| Deny access to this computer from the network | The user cannot connect to the computer remotely. | ? |
| Deny logon as a batch job | | ? |
| Deny logon as a service | | ? |
| Logon as a batch job | | ? |
| Logon as a service * | This right is used by background applications. The rights are required for the service to function | ? |
| Log on locally * | | All built-in groups, including Everyone, except Replicator |
| Privilege | Description | Groups |
| Act as part of the operating system | | ? |
| Add workstations to domain | | ? |
| Back up files directories * | The user can back up files or directories to storage media. | Administrators, Backup Operators |
| Bypass traverse checking * | Lets the user or group move through directory trees even if the group does not have permission to access the directories. Normally this right is given to Power Users. | Everyone |
| Change the system time * | Can change the current time. | Administrators, Power Users |
| Create a page file | The system memory pagefile size and location can be changed. | Administrators |
| Create a token object | | ? |
| Create permanent shared objects | | ? |
| Debug programs | Can debug threads | Administrators |
| Enable computer and user accounts to be trusted for delegation | | ? |
| Force shutdown from a remote system * | A system can be shutdown across the network. | Administrators, Power Users |
| Generate security audits | | ? |
| Increase quotas | | ? |
| Increase scheduling priority | Increase a processes execution priority. | Administrators, Power Users |
| Load and unload device drivers * | Device drivers may be added or removed from the system. | Administrators |
| Lock pages in memory | ? |
| Manage auditing and security log * | View auditing log files and control what the system audits. | Administrators |
| Modify firmware environment values | BIOS firmware may be changed. | Administrators |
| Profile single process | View a specific system performance counter. | Administrators, Power Users |
| Profile system performance | Check the system performance with Performance Monitor. | Administrators |
| Remove computer from docking station | | ? |
| Replace a process level token | | ? |
| Restore files and directories * | The user can restore files or directories from storage media. | Administrators, Backup Operators |
| Shut down the system * | Shut the system off. | Administrators, Backup Operators |
| Synchronize directory service data | | ? |
| Take Ownership of files or objects * | Make any objects owned by the user that is taking ownership. Ownership cannot be assigned to other users. | Administrators |
Domain controllers do not have a power users group. On the Domain Controllers, Server Operators are similar to the Administrator group on the Workstation with all rights.