User Account Control: Admin Approval Mode for the Built-in Administrator account

Information

User Account Control: Admin Approval Mode for the Built-in Administrator account

This security setting determines the behavior of Admin Approval mode for the Built-in Administrator account.

The options are:

Enabled: The Built-in Administrator will logon in Admin Approval Mode. By default any operation that requires elevation of privilege will prompt the Consent Admin to choose either Permit or Deny.

Disabled: The Built-in Administrator will logon in XP compatible mode and run all applications by default with full administrative privilege.

Default: Disabled

Solution

Policy Path: Security Options
Policy Setting Name: User Account Control: Admin Approval Mode for the Built-in Administrator account

See Also

https://techcommunity.microsoft.com/t5/microsoft-security-baselines/windows-server-2022-security-baseline/ba-p/2724685

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-6(5)

Plugin: Windows

Control ID: b6cdc9ba256ea763190f9c8abf588a72f0ef8fc64d2a13c18384fd4fce2b5235