Set up a NON-power user.
Admins can ONLY be Admins, but you can give a "guest account" certain permissions and they will NOT alter the Admin account at all.
You cannot delete the last Admin account either.
" a stand-a-lone workstation "
~ Why not just use the Admin account?
What I do is use Admin as User, and delete all accounts except the Guest account since you MUST have 1 Admin and 1 Guest account. Then I disable the Guest with the BIG lockout RED X, and I am safe as can be.
INFO:
"Guests have the same access as members of the Users group by default, except for the Guest account which is further restricted"
"Power Users possess most administrative powers with some restrictions. Thus, Power Users can run legacy applications in addition to certified applications"
"Users are prevented from making accidental or intentional system-wide changes. Thus, Users can run certified applications, but not most legacy applications"