Soru

Zorluk: OrtaWindows Security Settings and User Account Control

A user on a Windows 11 workstation reports that a legacy line-of-business application fails to save local configuration settings unless it is launched by right-clicking the icon and choosing 'Run as administrator'. The workstation is logged into by a Standard User account. The helpdesk technician wants to enable the user to save settings within the application without granting the account local administrator rights or lowering overall system User Account Control (UAC) security settings. Which of the following actions should the technician take?

  1. Grant the Standard User account explicit Modify permissions on the application's file folder and registry subkeys.Cevap
  2. B
    Open User Account Control Settings from the Control Panel and adjust the slider to 'Never notify'.
  3. C
    Configure Local Security Policy to set 'User Account Control: Behavior of the elevation prompt for standard users' to 'Automatically deny elevation requests'.
  4. D
    Add the account to the local Administrators group and enable 'Run this program as an administrator' on the executable shortcut.

Cevap

Grant the Standard User account explicit Modify permissions on the application's file folder and registry subkeys.
Granting explicit Modify permissions to the specific folder and registry keys used by the application resolves write access errors under a Standard User account without elevating the user's overall system privileges or disabling system security controls.

Adım Adım Çözüm

1
Identify the cause of the UAC elevation requirement for the application.
Legacy applications often require administrative access because they attempt to write configuration data to protected directories such as C:\Program Files or HKEY_LOCAL_MACHINE.
Standard user accounts lack write/modify rights to system-protected locations by default.
2
Apply targeted permission changes using the principle of least privilege.
Updating NTFS permissions on the application folder and registry key permissions for the application's specific registry path enables file and registry modifications.
This resolves the application failure while keeping the user account at a standard privilege level and maintaining UAC protection system-wide.

Anahtar Kavram

Principle of Least Privilege and UAC Application Security
Tahmini Süre:1m 15s
Bu soruyu puanla