Windows 11 baseline hardening administrator promots gone

jeff mcnabney 301 Reputation points
2022-03-15T20:57:47.617+00:00

After testing Win11 baseline scripts, noticed that the administrator prompt no longer appears, can't run cmd as admin, from non-admin users. Must log in as administrator. Looked through the gp's to see where this might be happening but no luck. Can anyone indicate where i will find the settings to at least unlock the Administrator prompt?

Windows for business | Windows Client for IT Pros | User experience | Other
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Limitless Technology 39,931 Reputation points
    2022-03-21T11:34:09.813+00:00

    Hi @jeff mcnabney

    It might be you have enabled the built-in Administrator account and have configured Admin Approval Mode, you must also configure the option Prompt for consent on the secure desktop. You can also configure this option from User Account Control, by typing UAC in the search box. From the User Account Control Settings dialog box, set the slider control to Notify me only when apps try to make changes to my computer.

    It is best practice to select the option Elevate without prompting minimizes the protection that is provided by UAC.

    You can get more info from here https://learn.microsoft.com/en-us/windows/security/threat-protection/security-policy-settings/user-account-control-behavior-of-the-elevation-prompt-for-administrators-in-admin-approval-mode

    Hope this answers your question :)
    Thank you.

    --
    --If the reply is helpful, please Upvote and Accept as answer--

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.