Soru

Zorluk: OrtaWindows Security Settings and User Account Control

A systems administrator is configuring Windows 11 Pro workstations used for automated nightly batch tasks. An administrative script assigned to run under a local administrator account fails to complete because User Account Control (UAC) pauses execution while waiting for interactive consent on the Secure Desktop. To allow automated background execution for administrative accounts while maintaining UAC protections for standard users, which Local Security Policy setting should be modified?

  1. User Account Control: Behavior of the elevation prompt for administrators in Admin Approval ModeCevap
  2. B
    User Account Control: Switch to the secure desktop when prompting for elevation
  3. C
    User Account Control: Run all administrators in Admin Approval Mode
  4. D
    User Account Control: Only elevate executables that are signed and validated

Cevap

Modify 'User Account Control: Behavior of the elevation prompt for administrators in Admin Approval Mode' to 'Elevate without prompting'.
The policy setting 'User Account Control: Behavior of the elevation prompt for administrators in Admin Approval Mode' explicitly controls how Windows handles privilege elevation for administrative accounts. Setting this policy to 'Elevate without prompting' allows applications and scripts executed by administrative accounts to automatically receive elevated rights without waiting for user input on the Secure Desktop.

Adım Adım Çözüm

1
Identify the cause of automated script failure
The background script running under an administrator account triggers an interactive UAC consent prompt on the Secure Desktop, stalling non-interactive batch execution.
By default, Windows prompts administrators for explicit consent before granting full administrative access tokens to tasks.
2
Access Local Security Policy (secpol.msc)
Navigate to Security Settings > Local Policies > Security Options.
Granular UAC elevation behaviors and privilege control policies are managed within Windows Security Options.
3
Configure elevation prompt behavior for administrators
Set 'User Account Control: Behavior of the elevation prompt for administrators in Admin Approval Mode' to 'Elevate without prompting'.
This specific setting allows tasks run by accounts with administrative privileges to automatically acquire elevated rights without requiring interactive user intervention.

Anahtar Kavram

Windows Local Security Policy UAC Elevation Settings
Bu soruyu puanla