Windows Vista Forums
Vista Forums Home Join Vista Forums Donate Vista Tutorials Tags

Welcome to Vista Forums we are your forum to discuss Windows Vista x64 and x86 systems. Whether you need help or just want to post an idea you have on Vista, this is the forum for you.
Register at Vista forums...the world biggest Windows Vista resource Join Vista Forums Now

Go Back   Vista Forums > Vista Newsgroups > Vista security

User Account Control (UAC) Cautions - Public Information

Closed Thread
 
Thread Tools Display Modes
Old 03-10-2007   #1 (permalink)
DavFChap
Guest
 
Posts: n/a

User Account Control (UAC) Cautions - Public Information

For the public, in general: Discussion regarding limitations of turning off User Account Control in Windows Vista Basic & Home (all versions)

Undocumented in KnowledgeBase articles, to date...architectural coverage exists within TechNet and addresses the following [very short] discussion

Background: TechNet; I strongly suggest you perform your own research regarding the following discussion. Windows Vista is such a new OS and has been in general distribution only a month when this opinion was written. We, as users and administrators, have much to learn regarding its architecture and interaction with its configuration and programs (APIs). Even though the OS was available for over a year in BETA, there remains widespread lack of driver support both with OEMs and within the OS itself. The same is true for extensions and software (APIs) presently on the shelves of retailers. I have, however, experienced very little problems with OEM pre-installed drivers, extensions and/or software. Vista is a memory HOG; the first line of defense against problematic behavior is 2GB RAM and double the RAM size in the paging file. Turn on System Restore!

Installing programs: Turning off UAC in user accounts, even though those accounts are granted Administrative rights can cause MSI to fail, esp. if it fails to propagate elevated installation rights, as needed. This has been observed with some Intuit & Symantec programs, most recently QuickBooks 2007 Premium & LiveUpdate, respectively and certainly exists within other APIs as well as having the potential for problematic driver installations and updates.

Installing and/or Running programs: The problem [for end-users] seems to lie within the Vista design, in that even though an account is already granted Administrative rights, policy defaults require elevated propagation [authentication to succeed] of rights before passing rights down to the API layer. The API layer may be MSI, an API, a component or components of an API, or a module called by MSI or an API to which it needs to pass values or retrieve values. When UAC is turned off, authentication fails because [of course] the prompt to the user (basis of UAC - to thwart unrestricted access to the system) to grant permission is turned off. Hence, authentication is indirectly turned off.

Security Policies (SecPol.msc): Policies in Vista Pro, Vista Premium, & Vista Enterprise can be modified to allow pass-thru of these rights even without assigning Administrative rights to a user account and with turning off UAC for that account. For the procedure(s), you will have to refer to the TechNet web site User Account Control Overview and Understanding and Configuring User Account Control in Windows Vista. However, Vista Basic & Home Editions do not allow modification to user or system level policies; as has any other Home Edition release. Therefore, non-business distribution networks for desktops, notebooks, TabletPCs, and handhelds [having been distributed largely with Vista Basic & Home Edition (or embedded versions)] lack sufficient controls to modify security policies in such a manner as to make it safe to turn off UAC.

This [problematic] design can further disrupt API execution within the API (as described above in Running Programs), even though it may have been pre-installed or originally installed with Administrative rights assigned. Apparently, utilization of either of Advanced Properties, Compatibility or Security settings within an API's shortcut properties remains ineffective in overriding security policy design within Vista Basic & Home Editions.

Conclusion: Assuming you, as a user have disabled UAC, develop or observe oddities, failures to execute, API startup/splash followed by immediate shutdown of the API, messages regarding program or module communications, MSI startups stacking up in Task Manager and never completing, (just to mention my most recent observations) then reconsider the impact of turning off UAC. It is likely that the issues discussed herein are far greater in performance impact than early experiences suggest, and as Microsoft strengthens the security policies in order to thwart trojans, viruses, phishing, adware, as well as other types of malware [both real and to be developed] UAC will experience further integration with AI in order to evolve in to Microsoft's vision of a 'dynamic protector.' We must learn to live with UAC while encouraging Microsoft to incorporate administrators' capacity to configure it within ALL versions of Vista and reduce redundancy and unnecessary interruption in daily productivity.

Disclaimer: The information offered herein is based upon my personal interpretation of TechNet articles and Community Discussions. It is offered for public viewing on an "as is" basis with no further warranty as to its accuracy, completeness or appropriateness in any particular situation. The opinions herein are based upon personal experiences and observations as both an end-user and computer technician. I hope you find the information useful and enlightening, and if so, please append your experiences and observations so that others may benefit from it.

David Chapman, A+, Net+, Microsoft Partner
davfchap@hotmail.com


 
Closed Thread

Thread Tools
Display Modes


Similar Threads
Thread Thread Starter Forum Replies Last Post
Help with User Account Control ronnell .NET General 6 07-15-2008 06:04 AM
Hidden user account information Firefly Vista account administration 3 06-08-2008 04:34 PM
Hidden user account information Firefly Vista General 2 06-08-2008 01:40 PM
How to Backup Vista user account information Balakumar Vista account administration 3 09-19-2007 05:47 PM
UAC - User Account Control David Sherman Vista account administration 7 07-31-2006 07:49 AM








Vistax64.com is an independent web site and has not been authorized,
sponsored, or otherwise approved by Microsoft Corporation.
"Windows Vista", the Start Orb, and related materials are trademarks of Microsoft Corp.
© Designer Media 2005-2008

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49