I want to enable remote desktop connection on my friends PC. Is it OK to be a remote user who has admin rights or is this a security issue? Also, if he is logged in already, will he get a pop up asking to allow this connection? If so, then two users will be logged in at once? Am I correctly understanding this? Thanks. P.S. My friend will be using Windows XP SP3 and so will I.

A remote user does not need to log on since the local user has already done that. In effect the remote user becomes the local user when the remote connection is allowed. The local user will receive a prompt to allow (or not allow) the remote connection.
The remote user has the same privileges on that account that the local user has on that account.
