Adding the "user" flag allows ordinary users to mount the device. I'd add gid=grpno too (where grpno is the numeric group number of a group that you want to allow to use /mnt/win - and add all users who should be able to access the windows partition into the relevant group).
Comment