Why has Microsoft not set up 'remote approval' for Admin elevation on a Standard Account (students, children, remote workers)?

Anonymous
2024-03-13T11:43:35+00:00

This has been an issue for years - and post Covid, even more of an issue.

There are good reasons for restricting a user to Standard account privileges for normal day-to-day operation - not just to protect the system from the user, but also from malicious activity (malware, hacking, viruses, trojans etc). As an Admin I still prefer to run in a Standard account and only access the Admin User account when required.

The issue is that if IT Admin no longer being immediately accessible (for various reasons) then the user runs into an issue with needing Admin privileges on occassion, usually in the middle of class, at a client site, at home the day before a critical meeting, etc. It can occur updating drivers for a printer, an application needing network permissions, and of course installing software.

Ignoring the responses "Why do they need it" and accepting the premise that they do, why has Microsoft not built in a simple solution for this, particularly with the existing implementation of managed accounts, family parental control, and Azure integration?

Potential Solutions
Microsoft already have most of the pieces of the puzzle to implement a simple solution to this, and these are likely already part of the existing support / software framework in place, but just not 'hooked in' to provide a working solution. Here are some of my thoughts on potential mechanisms to do this.

  1. Add a 'request remote approval' option to the 'Elevated Privileges required' popups so the user can request remote Admin help.
  2. The user could then select from a list of accounts on the local machine, a Microsoft Family parent, or a prearranged (or Registry key specified) account.
  3. A notification is then sent to the selected account (SMS, Microsoft Authenticator, Email or some other method) which includes information about the requesting user account, machine ID, and details of why the elevation is required (application details, permission requirements, etc - and maybe allow the user to add a comment to the request.
  4. The approval mechanism would ideally be done through a secure channel already in place - Microsoft Authenticator is a great candidate for this.
  5. To provide some protection from unauthorised action intercepting / creating fake requests / approvals there are already lots of options, but making it require that this facility be pre-configured on both ends (certificates?, PSK?) will add another layer of protection.

Unacceptable solutions available already:

  • give them an admin account,
  • wait until they can see an administrator
  • (not ideal) - get a remote session established with an administrator

***moved from Windows / Windows 11 / Security and privacy***

Windows for business | Windows Client for IT Pros | User experience | Remote desktop services and terminal services

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question. To protect privacy, user profiles for migrated questions are anonymized.

0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Anonymous
    2024-03-15T06:42:03+00:00

    Hello,

    Thank you for your question and for sharing your thoughts on potential solutions. Your feedback is valuable in this regard.

    You can upload your user experience and desired improvements about Microsoft products on the website below:

    Send feedback to Microsoft with the Feedback Hub app - Microsoft Support

    Microsoft will continue to evaluate and improve its products to provide the best possible user experience while maintaining a high level of security.

    Regards,

    Jacen Wang

    0 comments No comments