Accounts: User Account Control (UAC) must run all administrators in Admin Approval Mode, enabling UAC

417239de-2859-45e4-9a8f-43c47f4daedb

UAC is a security mechanism for limiting the elevation of privileges, including administrative accounts, unless authorized. This setting enables UAC. Satisfies: SRG-OS-000373-GPOS-00156, SRG-OS-000373-GPOS-00157

Remediation

To fix this configure the policy value for
Computer Configuration
|_ Windows Settings
|_ Security Settings
|_ Local Policies
|_ Security Options
|_ "User Account Control: Run all administrators in Admin Approval Mode" to "Enabled".

STIG: Server:
2022: https://stigviewer.com/stigs/microsoft_windows_server_2022/2023-09-11/finding/V-254488
2019: https://stigviewer.com/stigs/microsoft_windows_server_2019/2023-09-11/finding/V-205813

Desktop
W11: https://stigviewer.com/stigs/microsoft_windows_11/2023-09-29/finding/V-253474
W10: https://stigviewer.com/stigs/microsoft_windows_10/2023-09-29/finding/V-220950

NIST 800-53 rev4: CM-2(2), CM-6(1)
NIST 800-53 rev5: CM-2(2), CM-6(1)
SRG-OS-000373-GPOS-00157, SRG-OS-000373-GPOS-00156
MITRE Att&k: T1087, T1087.001, T1087.002, T1546.011, T1548, T1548.002