Real Geek Forums  

Go Back   Real Geek Forums > Archives > Operating Systems > Windows Vista > Windows Vista Administration

Notices

Reply

Disable UAC for all admins (not just for the SID -500 Administrator)but enable it for Standard Users

 

LinkBack Thread Tools Display Modes
Old 10-16-2007, 06:34 PM   #1 (permalink)
Default Disable UAC for all admins (not just for the SID -500 Administrator)but enable it for Standard Users

I want to achieve, that administrative accounts are completely free,
they shall not be restricted by UAC.
I can do that for the Root-Administrator-Account, the one with the -500
SID. But I want to free "john doe", if he is Domain Administrator.

"Elevate without prompting" is not adequate, because programs that do
not force an elevation of rights ("asInvoker") would run with the
stripped down token.

So, why can't I do that? Or: how? Any ideas?

Thanks Thorsten
Thorsten Butz
Guest
 
Posts: n/a
Reply With Quote  
Old 10-17-2007, 03:51 AM   #2 (permalink)
Default RE: Disable UAC for all admins (not just for the SID -500 Administrator) but enable it for Standard Users

Hello Thorsten,

Thank you for using newsgroup!

As far as I know, by default the built-in Administrator account is not
being controlled by UAC. However, we can modify the following local
security policy to enable UAC for built-in Administrator account:
Computer Configuration\Windows Settings\Security Settings\Local
Policies\Security Options\User Access Control: Admin Approval Mode for the
Built-in Administrator account

We cannot enable/disable UAC for any other particular user accounts. It is
by design behavior in Windows Vista.

Thanks & Regards,

Ken Zhao

Microsoft Online Support
Microsoft Global Technical Support Center

Get Secure! - www.microsoft.com/security <http://www.microsoft.com/security>
================================================== ==
When responding to posts, please "Reply to Group" via your newsreader so
that others may learn and benefit from your issue.
================================================== ==
This posting is provided "AS IS" with no warranties, and confers no rights.





Ken Zhao [MSFT]
Guest
 
Posts: n/a
Reply With Quote  
Old 10-17-2007, 05:40 PM   #3 (permalink)
Default Re: Disable UAC for all admins (not just for the SID -500 Administrator)but enable it for Standard Users

Hello Ken!

17.10.2007 05:51, Ken Zhao [MSFT]s Mail:
Quote:
> As far as I know, by default the built-in Administrator account is not
> being controlled by UAC. However, we can modify the following local
> security policy to enable UAC for built-in Administrator account:
> Computer Configuration\Windows Settings\Security Settings\Local
> Policies\Security Options\User Access Control: Admin Approval Mode for the
> Built-in Administrator account
You are partially right: the built-in Admin account ist not controlled
by UAC (by default).

Configuring the gpo-setting above is equal to disabling the UAC
completely. The setting's caption is unclear/mistakeble: you do not
disable the UAC for admins, you do disable the UAC at all, Standard
users are no longer controlled by UAC, too.

Thorsten
Thorsten Butz
Guest
 
Posts: n/a
Reply With Quote  
Old 10-17-2007, 06:16 PM   #4 (permalink)
Default Re: Disable UAC for all admins (not just for the SID -500 Administrator)but enable it for Standard Users

Sorry, i made a mistake reading your reply:
I thought of this setting (but you didnt mention this one):

"User Account Control: Run all administrators in Admin Approval Mode"

This is the setting that I focussed on. I can not understand, why this
"design" was chosen. I want to enable UAC for standard users, and
disabled it for any administrative account, not just the built-in.

Thorsten

17.10.2007 05:51, Ken Zhao [MSFT]s Mail:
Quote:
> Computer Configuration\Windows Settings\Security Settings\Local
> Policies\Security Options\User Access Control: Admin Approval Mode for the
> Built-in Administrator account
Thorsten Butz
Guest
 
Posts: n/a
Reply With Quote  
Old 10-18-2007, 09:45 AM   #5 (permalink)
Default Re: Disable UAC for all admins (not just for the SID -500 Administrator) but enable it for Standard Users

Hi Thorsten,

Thanks for your reply and this is by design behavior in Windows Vista. I do
understand your concerns. From my point of view, I understand your feeling
and how frustrated when you find that our product cannot meet your needs.
So, it is my pleasure to help you to reflect your recommendation to the
proper department for their consideration.

In addition, please feel free to submit your suggestion on our product to
the following link. Our Product Group reviews the suggestions submitted by
our customers. Your feedback is valuable for us to improve our products and
increase the level of service provided.

https://support.microsoft.com/common...08&showpage=1&
ws=search

Thanks & Regards,

Ken Zhao

Microsoft Online Support
Microsoft Global Technical Support Center

Get Secure! - www.microsoft.com/security <http://www.microsoft.com/security>
================================================== ==
When responding to posts, please "Reply to Group" via your newsreader so
that others may learn and benefit from your issue.
================================================== ==
This posting is provided "AS IS" with no warranties, and confers no rights.



Ken Zhao [MSFT]
Guest
 
Posts: n/a
Reply With Quote  
Reply

Tags
None

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads

Thread Thread Starter Forum Replies Last Post
Disable standard users manage another account drunk3nrabbit Windows Vista Administration 2 03-28-2007 12:13 AM
DON'T DISABLE the UAC and be happy to use a Standard Account mik Windows Vista Security 8 11-25-2006 11:01 AM
Standard Users Frankydp Windows Vista Administration 4 11-09-2006 12:17 PM
is it necessary for new users to be local admins? Chip Orange Windows XP Configuration & Management 2 04-15-2005 01:51 AM
Don't want RD users to be Admins - log off problem No Spam Windows XP Work Remotely 4 10-17-2003 09:01 PM


All times are GMT. The time now is 05:55 PM.


Powered by vBulletin® Version 3.7.1
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Copyright © 2005 - 2007 RealGeek.com. All rights reserved.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90