it seems to be setup correctly, the only thing i would change, IF you need to is:
-On the Windows Logon section I left it as Not Allowed.
change that to allow all, that way( assuming the PC is set up with administrator accounts) you can connect to the windows log on screen and pick and account to log in to.
IF you have a single windows log on only and that account for normal everyday use is set to have administrator privileges, i would use that account, to add and administrator account( with a password), then log out, log into the NEW administrator account and change the first account to a "standard user".
They key factor is admin-rights. Malware can't spread, gather information or send it to someone else without admin-rights. You don't need them for everyday computer work - just for installing, removing and configuring applications and system settings.
How to set up a user account that doesn't have admin-rights when you are using the standard account you created at setup:
Symbols:
-> means user interaction, usually a left click
"" content in between is the name of the actual button you should press
-> Start -> Control Panel -> "Add or remove user accounts"
-> "Create a new account" -> choose a name and check "Administrator" -> "Create account"
You're back at the Manage accounts window. Click on your newly created admin account -> "create a password" -> enter password and password hint -> "Create password" -> "Manage another account"
You're back at the Manage accounts window. -> chose the old account you used so far -> "Change account type" -> check "Standard user" -> "Change Account Type".
Sign off or restart your computer.
You're done, that's it. A high percentage of all malware that exists now has no chance to ever compromise your system from now on.