![]() |
![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() |
|
Welcome to Vista Forums we are your forum to discuss Windows Vista x64 and x86 systems. Whether you need help or just want to post an idea you have on Vista, this is the forum for you.
br> br> |
| |||||||
![]() |
| | Thread Tools | Display Modes |
| | #1 (permalink) |
| Guest | Disable UAC for all admins (not just for the SID -500 Administrator)but enable it for Standard Users I want to achieve, that administrative accounts are completely free, they shall not be restricted by UAC. I can do that for the Root-Administrator-Account, the one with the -500 SID. But I want to free "john doe", if he is Domain Administrator. "Elevate without prompting" is not adequate, because programs that do not force an elevation of rights ("asInvoker") would run with the stripped down token. So, why can't I do that? Or: how? Any ideas? Thanks Thorsten |
My System Specs![]() |
| | #2 (permalink) |
| Guest | RE: Disable UAC for all admins (not just for the SID -500 Administrator) but enable it for Standard Users Hello Thorsten, Thank you for using newsgroup! As far as I know, by default the built-in Administrator account is not being controlled by UAC. However, we can modify the following local security policy to enable UAC for built-in Administrator account: Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options\User Access Control: Admin Approval Mode for the Built-in Administrator account We cannot enable/disable UAC for any other particular user accounts. It is by design behavior in Windows Vista. Thanks & Regards, Ken Zhao Microsoft Online Support Microsoft Global Technical Support Center Get Secure! - www.microsoft.com/security <http://www.microsoft.com/security> ==================================================== When responding to posts, please "Reply to Group" via your newsreader so that others may learn and benefit from your issue. ==================================================== This posting is provided "AS IS" with no warranties, and confers no rights. |
My System Specs![]() |
| | #3 (permalink) | ||||||||||||
| Guest | Re: Disable UAC for all admins (not just for the SID -500 Administrator)but enable it for Standard Users Hello Ken! 17.10.2007 05:51, Ken Zhao [MSFT]s Mail:
by UAC (by default). Configuring the gpo-setting above is equal to disabling the UAC completely. The setting's caption is unclear/mistakeble: you do not disable the UAC for admins, you do disable the UAC at all, Standard users are no longer controlled by UAC, too. Thorsten | ||||||||||||
My System Specs![]() | |||||||||||||
| | #4 (permalink) | ||||||||||||
| Guest | Re: Disable UAC for all admins (not just for the SID -500 Administrator)but enable it for Standard Users Sorry, i made a mistake reading your reply: I thought of this setting (but you didnt mention this one): "User Account Control: Run all administrators in Admin Approval Mode" This is the setting that I focussed on. I can not understand, why this "design" was chosen. I want to enable UAC for standard users, and disabled it for any administrative account, not just the built-in. Thorsten 17.10.2007 05:51, Ken Zhao [MSFT]s Mail:
| ||||||||||||
My System Specs![]() | |||||||||||||
| | #5 (permalink) |
| Guest | Re: Disable UAC for all admins (not just for the SID -500 Administrator) but enable it for Standard Users Hi Thorsten, Thanks for your reply and this is by design behavior in Windows Vista. I do understand your concerns. From my point of view, I understand your feeling and how frustrated when you find that our product cannot meet your needs. So, it is my pleasure to help you to reflect your recommendation to the proper department for their consideration. In addition, please feel free to submit your suggestion on our product to the following link. Our Product Group reviews the suggestions submitted by our customers. Your feedback is valuable for us to improve our products and increase the level of service provided. https://support.microsoft.com/common...08&showpage=1& ws=search Thanks & Regards, Ken Zhao Microsoft Online Support Microsoft Global Technical Support Center Get Secure! - www.microsoft.com/security <http://www.microsoft.com/security> ==================================================== When responding to posts, please "Reply to Group" via your newsreader so that others may learn and benefit from your issue. ==================================================== This posting is provided "AS IS" with no warranties, and confers no rights. |
My System Specs![]() |
![]() |
| Thread Tools | |
| Display Modes | |
| |
Similar Threads | ||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| DEP - Enable or Disable | Brink | Tutorials | 71 | 3 Weeks Ago 06:58 PM |
| Index - Enable or Disable | Brink | Tutorials | 31 | 08-21-2008 07:24 AM |
| Regedit - Enable or Disable | Brink | Tutorials | 14 | 08-05-2008 02:10 PM |
| .Net 1.1 moved to Windows Server 2008 Enterprise does not work for regular users, but works for Admins | LVP | Vista security | 4 | 03-24-2008 09:51 AM |
| Disable standard users manage another account | drunk3nrabbit | Vista account administration | 2 | 03-27-2007 07:13 PM |