Accounts: UIAccess applications must not be allowed to prompt for elevation without using the secure desktop

80e6af5a-3633-408e-b890-8b7581adda66

User Account Control (UAC) is a security mechanism for limiting the elevation of privileges, including administrative accounts, unless authorized. This setting prevents User Interface Accessibility programs from disabling the secure desktop for elevation prompts.

Remediation

To fix this configure the policy value for
Computer Configuration
|_ Windows Settings
|_ Security Settings
|_ Local Policies
|_ Security Options
|_ "User Account Control: Allow UIAccess applications to prompt for elevation without using the secure desktop" to "Disabled".

STIG: Server:
2022: https://www.stigviewer.com/stig/microsoft_windows_server_2022/2024-06-14/finding/V-254483
2019: https://www.stigviewer.com/stig/windows_server_2019/2020-06-15/finding/V-93521 / https://www.stigviewer.com/stig/microsoft_windows_server_2019/2024-06-14/finding/V-205716
2016: https://www.stigviewer.com/stig/windows_server_2016/2020-06-16/finding/V-73709 / https://www.stigviewer.com/stig/microsoft_windows_server_2016/2024-02-21/finding/V-225062

NIST 800-53: AC-6(8)
CAT: II
CCI: CCI-001084
Rule-ID|SV-254483r958518_rule
STIG-ID: WN22-SO-000390
Vuln-ID:V-254483, V-V-93521, V-205716, V-73709, V-225062
CMMC v2.1 L3: SI.L3-3.14.3e
MITRE Att&k: T1087, T1087.001, T1087.002, T1546.011, T1548, T1548.002