Quiz Entry - updated: 2026.09.29
Which UAC settings make up a hardened baseline, and what does each one achieve?
Admin Approval Mode for everyone (including the built-in Administrator), admins prompted for consent on the secure desktop, standard users' elevation requests denied automatically, plus installer detection, UIAccess and virtualization settings enabled.
| Setting | Value | Why |
|---|---|---|
| Admin Approval Mode for the built-in Administrator | Enabled | Removes the one account that would otherwise always run with full rights |
| Run all administrators in Admin Approval Mode | Enabled | This is the master switch: UAC on |
| Elevation prompt for administrators | Prompt for consent on the secure desktop | The prompt appears on an isolated desktop that other programs cannot read or click, so malware cannot fake or auto-approve it |
| Elevation prompt for standard users | Automatically deny | Standard users are not asked for admin credentials at all, so they cannot be tricked into typing them in, and they go through the helpdesk instead |
| Detect application installations and prompt | Enabled | Setup programs trigger elevation even if they don't declare it |
| Only elevate UIAccess apps in secure locations | Enabled | Accessibility-type apps may only elevate from protected folders such as Program Files |
| Virtualize file and registry write failures | Enabled | Old programs that write to protected locations are redirected to a per-user copy instead of failing |
Set via GPO at Computer Configuration > Policies > Windows Settings > Security Settings > Local Policies > Security Options.
Go deeper:
Microsoft Learn: UAC settings and configuration — every UAC policy with its options and default.