Windows 10: Why has Microsoft not set up 'remote approval' for Admin elevation on a Standard Account...

Discus and support Why has Microsoft not set up 'remote approval' for Admin elevation on a Standard Account... in Windows 10 Gaming to solve the problem; This has been an issue for years - and post Covid, even more of an issue. There are good reasons for restricting a user to Standard account privileges... Discussion in 'Windows 10 Gaming' started by Adam Marshall2, Mar 13, 2024.

  1. Why has Microsoft not set up 'remote approval' for Admin elevation on a Standard Account...


    This has been an issue for years - and post Covid, even more of an issue. There are good reasons for restricting a user to Standard account privileges for normal day-to-day operation - not just to protect the system from the user, but also from malicious activity malware, hacking, viruses, trojans etc. As an Admin I still prefer to run in a Standard account and only access the Admin User account when required.The issue is that if IT Admin no longer being immediately accessible for various reasons then the user runs into an issue with needing Admin privileges on occassion, usually in the mi

    :)
     
    Adam Marshall2, Mar 13, 2024
    #1
  2. zebal Win User

    Using same password for both Local Admin and Standard accounts?

    You should not use the same password because that's almost the same thing as not having standard user account but just using administrative account.

    There is a technique call "privilege escalation", and if you have same password you'll make attacker's job easier.

    Keep in mind that for this to be most effective you need UAC maxed out, this way "privilege escalation" scenario is less likely.

    If having separate password for each account is such a problem, make your standard user account password short, ex. max. 5 characters, because loosing control of standard account isn't problem at all for local system; important is that Admin account is min. 8 chars with complexity policy in place. (loosing Admin account means loosing everything else)

    If you want to go one step further and make your accounts even more safe make sure user accounts are not enumerated during login or UAC approval.

    Also important step is to prevent keyloggers from capturing your password as you type them, to ensure this does not happen never use hardware keyboard for UAC or login prompt, use virtual keyboard instead.

    If you use remote access to your computer make sure CTRL + ALT + DEL is required prior to logging in.
     
    zebal, Mar 13, 2024
    #2
  3. Elnegaard Win User
    User Account Control and Admin Approval mode

    Thanks for the replay.

    I'm not sure I have explained my problem correctly

    I have a built in Com X card running som Sw that demands Admin privilegies to start up.

    by setting, Run all administrators in Admin Approval mode to Disable, the Sw can starup with out user doing anything.

    But i the customer access the build in PC by remote desktop the customer can change User Account Control Settings in the user control.

    That possibility I would like to disable.

    As I understand it that is not done by the suggestion, or do I miss understand

    Br Rene
     
    Elnegaard, Mar 13, 2024
    #3
  4. Why has Microsoft not set up 'remote approval' for Admin elevation on a Standard Account...

    Elevating/Accquiring the Admin Token in Administrator vs Standard Accounts in Windows

    I've recently been confused by how UAC works between Standard accounts and Administrator accounts,

    As we all know, when UAC is turned on, UAC allows Standard Accounts or Administrator accounts in Admin Approval Mode to gain access to the administrator token in order to perform tasks that require administrative access to the machine - allowing us to switch
    tokens without switching users,

    However, it appears that switching tokens is not really what happens: A while ago, I ran an application that would modify the shell (explorer.exe). I ran the program in a Standard Account, but it needed elevated access: therefore, I used UAC to supply admin
    credentials so it could complete. I did not seen any change to the shell; I then logged into the administrator account whose credentials I used and I saw that the shell in that account had been changed, which was obviously not what I wanted

    It appeared to me that UAC was just basically a "Run-as user" type deal where it actually ran the program as that user. This meant that I wasn't just running it elevated: I was literally running the program as that user,

    My question is: is it possible for a standard account to use the administrator token but actually run the program as a standard user and use the current user's profile? Otherwise, it seems to me that if you need to do any administrator tasks, you are pretty
    much required to log in to an administrator account which defeats the whole purpose of UAC - since UAC runs a program as the administrator, rather than using just the administrator rights,

    Is this separation of token and profile possible? Or do all users just have to be administrators in that case? It seems to me this would account for many organizations just granting full administrator access to all users,

    Can someone please shed some light on this?

    I would like to know if it would have been possible to supply an administrator token to the said program, but run that program in the current user account, not the user account of the administrator whose credentials were supplied - in other words, would it
    have been possible to modify the shell in the Standard account with that program? The goal would be to launch the process as the logged in user (regardless of current privileges) with administrative rights, not as a process under an account with admin rights.

    I am not referring to Admin Approval Mode or how UAC works. I already know that if UAC is set to a secure setting, even Administrators will be prompted and unless it is turned off, administrators use the standard token by default. I am talking about when
    the administrator token is gained, is it possible to still run the process as the logged in user, just with the admin token? (not using Run As 'user' but maybe something like run as/with 'token'), etc... In this way, it would be using generic administrative
    privileges rather than one user's administrative privileges.

    Is this at all possible, or have I just pointed out a feature not in Windows by design or something?

    Would I, to achieve the goal described here, have to perhaps turn the standard account into an administrator account any time anything that requires elevation needs to be done, and then turn it back into a standard account when done? Based on comments, it appears
    that this is not possible and that seems to be a flaw in the OS because it makes UAC basically useless.

    Hope this makes sense,
     
    InterLinked CEO, Mar 13, 2024
    #4
Thema:

Why has Microsoft not set up 'remote approval' for Admin elevation on a Standard Account...

Loading...
  1. Why has Microsoft not set up 'remote approval' for Admin elevation on a Standard Account... - Similar Threads - Why has Microsoft

  2. Why has Microsoft not set up 'remote approval' for Admin elevation on a Standard Account...

    in Windows 10 Software and Apps
    Why has Microsoft not set up 'remote approval' for Admin elevation on a Standard Account...: This has been an issue for years - and post Covid, even more of an issue. There are good reasons for restricting a user to Standard account privileges for normal day-to-day operation - not just to protect the system from the user, but also from malicious activity malware,...
  3. Blocked admin account by standard account

    in Windows 10 Gaming
    Blocked admin account by standard account: Hi ! please someone help me i need to tell you that i was setting some fuctions for me ..... ya i know i stupid but somehow i changed my account type to standard and block admin account ....i can't get admin powers and admin account is gone somewhere i need help please :...
  4. Blocked admin account by standard account

    in Windows 10 Software and Apps
    Blocked admin account by standard account: Hi ! please someone help me i need to tell you that i was setting some fuctions for me ..... ya i know i stupid but somehow i changed my account type to standard and block admin account ....i can't get admin powers and admin account is gone somewhere i need help please :...
  5. Eject a USB device remotely with standard non-admin account

    in Windows 10 Network and Sharing
    Eject a USB device remotely with standard non-admin account: I have a desk and a table around a corner with my Windows 10 and Windows 7 computers on them. The two towers are practically right next to each other, but they keyboards, mice, and monitors are farther apart. I needed to make three identical USB sticks with almost 30gb of...
  6. Why is a standard account vs admin account recommended?

    in Windows 10 Customization
    Why is a standard account vs admin account recommended?: Why is Microsoft recommending a standard account vs admin account when setting up Windows on a brand new device? https://answers.microsoft.com/en-us/windows/forum/windows_10-other_settings/why-is-a-standard-account-vs-admin-account/33d9babe-3309-41e8-8743-305f1aa64705
  7. User admin account to make changes that show up in standard account?

    in User Accounts and Family Safety
    User admin account to make changes that show up in standard account?: If I login to the administrator account to make changes, I naturally want any changes I make to appear in the standard user account since that is the one I am making changes for. Does this happen automatically or do I have to do something special to make sure it always works...
  8. Set up admin account on system with standard account only

    in User Accounts and Family Safety
    Set up admin account on system with standard account only: Hello everyone. This is my first post on Ten Forums. How can I create an admin account on a system that only has a standard user account? I suspect that the answer is that I can't, but I live in hope. I can't provide specific details of the PC in question because it's...
  9. Admin approval

    in User Accounts and Family Safety
    Admin approval: Hi gang, need a little help ! I just did a recovery on this computer & everytime i go to download anything it ask me for admin approval, i want to turn this off !! Any help appreciated ! Thanks Chuck 85906
  10. Admin elevation

    in Windows 10 Support
    Admin elevation: I hate appearing stupid, but it is the only way I learn... I have two user accounts on this computer, one as Administrator and the other as, well, let's call it "me". Both are Administrator accounts. So why is it that I regularly am either told or asked to elevate...