Yeah see this is exactly my point. Ok say im logged in as an administrator ( which i wont use to surf the web but lets just pretend ) and I start surfing the web... I hit a malicous website that knows about a new exploit that I havent patched yet or simply m$ is unaware of yet... If they do exploit ie it will be able to infect system files.. delete system files or pretty much anything that an administrator can do... Of course there are ie settings that can prevent this.. Different security zones, etc etc.. But this will never garantee safety.. If a user such as admin/power user or even a regular user.. I want to be able to restrict access to files for an application no matter who runs it. ntfs would solve the problem if i could force ie to run on an unpriveledged account. I could create an account called IE_USR.. That would have access to documents and settings only... Then no matter what happened to the browser the ntfs permissions would trap any attempt to harm critical files. Even if Administrator is using it. I think this should be a requirement for all applications.. it could prevent the spreading of virii to the system.. why should an application be given full rights such as an administrator. It should be sortof jailed into the files/folders that it only needs. In fact defaulting executables to no access would be fantastic. Then creating policies on the application for what actions it can perform. This would be very secure.. virii couldnt spread.