Soru

Zorluk: OrtaWindows Security Settings and User Account Control

A security technician needs to configure a standalone Windows 11 Pro workstation so that standard user accounts are automatically denied elevation requests without displaying a UAC prompt. Place the administrative configuration steps in the correct chronological order from first to last.

  1. 1Open the Run dialog box, type secpol.msc, and press Enter.
  2. 2Expand Security Settings > Local Policies and select Security Options.
  3. 3Double-click User Account Control: Behavior of the elevation prompt for standard users.
  4. 4Set the local security setting dropdown to Automatically deny elevation requests and click OK.

Cevap

The correct order of administrative steps is: 1) Open the Run dialog box, type secpol.msc, and press Enter -> 2) Expand Security Settings > Local Policies and select Security Options -> 3) Double-click User Account Control: Behavior of the elevation prompt for standard users -> 4) Set the local security setting dropdown to Automatically deny elevation requests and click OK.
To enforce auto-denial of elevation requests for standard users on Windows Pro or Enterprise editions, an administrator must launch the Local Security Policy console (secpol.msc), navigate to Security Settings > Local Policies > Security Options, locate 'User Account Control: Behavior of the elevation prompt for standard users', and change its value to 'Automatically deny elevation requests'.

Adım Adım Çözüm

1
Launch the Local Security Policy management console using the command secpol.msc.
The Local Security Policy window opens.
Fine-grained UAC behavior rules for distinct account types cannot be set in Control Panel and require the secpol.msc console.
2
Navigate through the policy tree under Security Settings to Local Policies, then select Security Options.
The right pane displays all configurable security option policies.
All administrative User Account Control policies reside within the Security Options folder.
3
Locate and open 'User Account Control: Behavior of the elevation prompt for standard users'.
The policy properties dialog appears.
This specific policy determines whether standard users receive a credential prompt or are blocked directly.
4
Change the security setting to 'Automatically deny elevation requests' and save changes.
Standard users will no longer see UAC prompts when trying to run administrative tasks; requests fail immediately.
Selecting this option fulfills the security requirement to enforce automatic denial without prompt interaction.

Anahtar Kavram

Configuring UAC elevation prompt behavior for standard accounts using Local Security Policy (secpol.msc)
Tahmini Süre:1m 30s
Bu soruyu puanla