LOGBOOK

HELP

Quiz Entry - updated: 2026.09.29

Which UAC settings make up a hardened baseline, and what does each one achieve?

Admin Approval Mode for everyone (including the built-in Administrator), admins prompted for consent on the secure desktop, standard users' elevation requests denied automatically, plus installer detection, UIAccess and virtualization settings enabled.

Setting Value Why
Admin Approval Mode for the built-in Administrator Enabled Removes the one account that would otherwise always run with full rights
Run all administrators in Admin Approval Mode Enabled This is the master switch: UAC on
Elevation prompt for administrators Prompt for consent on the secure desktop The prompt appears on an isolated desktop that other programs cannot read or click, so malware cannot fake or auto-approve it
Elevation prompt for standard users Automatically deny Standard users are not asked for admin credentials at all, so they cannot be tricked into typing them in, and they go through the helpdesk instead
Detect application installations and prompt Enabled Setup programs trigger elevation even if they don't declare it
Only elevate UIAccess apps in secure locations Enabled Accessibility-type apps may only elevate from protected folders such as Program Files
Virtualize file and registry write failures Enabled Old programs that write to protected locations are redirected to a per-user copy instead of failing

Set via GPO at Computer Configuration > Policies > Windows Settings > Security Settings > Local Policies > Security Options.

Go deeper:

From Quiz: ISLAB / Access Management with Active Directory | Updated: Sep 29, 2026