Accounts: User Account Control (UAC) approval mode for the built-in Administrator must be enabled

b505fc16-70d3-4275-bcc5-02fac2fdb3af

User Account Control (UAC) is a security mechanism for limiting the elevation of privileges, including administrative accounts, unless authorized. This setting configures the built-in Administrator account so that it runs in Admin Approval Mode.

Remediation

To fix this configure the policy value for:
Computer Configuration
|_ Windows Settings
|_ Security Settings
|_ Local Policies
|_ Security Options
|_ User Account Control: Admin Approval Mode for the Built-in Administrator account to "Enabled".

STIG: Server
2022: https://www.stigviewer.com/stig/microsoft_windows_server_2022/2022-08-25/finding/V-254482
2019: https://www.stigviewer.com/stig/microsoft_windows_server_2019/2022-03-01/finding/V-205811 / https://www.stigviewer.com/stig/windows_server_2019/2020-06-15/finding/V-93431
2016: https://www.stigviewer.com/stig/microsoft_windows_server_2016/2022-03-01/finding/V-225061 / https://www.stigviewer.com/stig/windows_server_2016/2020-06-16/finding/V-73707

Desktop:
W11: https://www.stigviewer.com/stig/microsoft_windows_11/2022-06-24/finding/V-253468
W10: https://www.stigviewer.com/stig/microsoft_windows_10/2022-04-08/finding/V-220944 / https://www.stigviewer.com/stig/windows_10/2021-08-18/finding/V-220944

STIG: SRG-OS-000373-GPOS-00157, SRG-OS-000373-GPOS-00156
NIST 800-53: CM-6(a),IA-11
PCI v3.2: 8.1.8
PCI v4: 8.2.8
SIG: H.7.10, H.7.10.1, H.20.1
STIG Finding ID: V-73707, V-225061, V-205811, V-93431, V-254482, V-220944, V-253468
MITRE Att&k: T1087, T1087.001, T1087.002, T1546.011, T1548, T1548.002