Soru

Zorluk: Çok zorWindows Security Settings and User Account Control

A tier-2 helpdesk technician is providing remote assistance to a user on a Windows 11 Enterprise workstation. Whenever an administrative command or application requiring privilege elevation is launched during the remote session, the technician's remote screen goes completely black, and control is temporarily lost until the local user interacts with the prompt. Corporate policy requires that User Account Control (UAC) remain active and continue prompting for elevation. Which Local Security Policy setting should the technician modify on the target workstation to allow remote management tools to display and interact with elevation prompts without turning off UAC?

  1. Disable the 'User Account Control: Switch to the secure desktop when prompting for elevation' policy setting.Cevap
  2. B
    Change the 'User Account Control: Behavior of the elevation prompt for administrators in Admin Approval Mode' policy setting to 'Elevate without prompting'.
  3. C
    Grant the standard user account Full Control NTFS permissions on C:\Windows\System32.
  4. D
    Open User Accounts in Control Panel and adjust the User Account Control slider to 'Never notify'.

Cevap

Disable the 'User Account Control: Switch to the secure desktop when prompting for elevation' policy setting.
When UAC triggers an elevation prompt, Windows switches to the Secure Desktop by default to prevent malicious applications from intercepting user credentials. Because standard user-mode remote control software cannot capture the Secure Desktop, the remote session displays a black screen. Disabling the policy setting 'User Account Control: Switch to the secure desktop when prompting for elevation' via secpol.msc forces UAC prompts to appear on the standard user desktop, allowing remote support agents to view and handle prompts while maintaining active UAC elevation rules.

Adım Adım Çözüm

1
Analyze the technical symptom described in the remote administration scenario.
Identified that the remote viewer goes black because Windows UAC switches context to the Secure Desktop (Winlogon desktop running at SYSTEM privileges), which non-system level remote software cannot screen-capture.
By default, UAC dims the desktop and isolates the credential prompt on a separate desktop to prevent software hooks or malware spoofing.
2
Evaluate the administrative requirement against possible UAC policy adjustments.
UAC notifications must remain enabled, ruling out solutions that bypass or turn off elevation prompts.
Corporate policy dictates that administrative privileges must still require explicit elevation approval.
3
Select the specific Local Security Policy (secpol.msc) setting that modifies desktop switching behavior while retaining prompts.
Disabling 'User Account Control: Switch to the secure desktop when prompting for elevation' presents UAC prompts on the interactive desktop.
This allows the remote support agent's application mirror to capture the prompt window and receive remote keyboard/mouse inputs.

Anahtar Kavram

Windows UAC Secure Desktop vs Interactive Desktop Isolation in Remote Administration
Bu soruyu puanla