Welcome to Vista Banter. You are currently viewing our boards as a guest which gives you limited access to view most discussions, articles and access our other FREE features. By joining our free community you will have access to ask questions and reply to others posts, upload your own photos and access many other special features. Registration is fast, simple and absolutely free so please, join our community today! If you have any problems with the registration process or your account login, please contact contact support. |
|
Security and Windows Vista A forum for discussion on security issues with Windows Vista. (microsoft.public.windows.vista.security) |
|
LinkBack | Thread Tools | Display Modes |
|
|||
Disabling UAC doesn't actually decrease security?
With UAC enabled in Vista build 5536, I get confirmation prompts in admin
accounts, and I get password dialog boxes in standard user accounts. And of course standard users can't read each other's home directories. Then I ran secpol.msc and under Local Policies\Security Options I disabled User Account Control: Run all administrators in Admin Approval Mode, and then rebooted. Now, as expected, admin accounts silently grant privilege elevation and no longer give confirmation prompts, but in standard user accounts, instead of getting a password dialog or a silent granting of privilege elevation, I get automatic denial. And standard users still can't read each other's home directories. So, if non-admin users are using standard user accounts, and the admin accounts are used only to run trusted software, then what security is actually lost by disabling UAC? Standard user accounts haven't gained any new privileges by having UAC disabled. |