-
Recently I came across a new setting under Local Policies in security settings in GPO called User Account Control: Configure type of Admin Approval Mode. The options included Legacy Admin approval mode (default) and Admin Approval Mode with Administrator Protection. (found in Computer config > Windows Settings > Security settings > Local Policies > Security options > User Account Control: Configure type of Admin Approval Mode) The Explain tab doesn't really give many details on either option and the general info given is too vague. The link at the bottom leads to nowhere and I couldn't find any documentation regarding this as well. Any idea what this might be? Is this related to admin-less windows David Weston mentioned in his black-hat talk? |
Beta Was this translation helpful? Give feedback.
Replies: 2 comments 4 replies
-
Hi, If it turns out to be something useful (which it looks like it) i'll add it to the UAC category if the MSFT security baselines for 24H2 don't include it. |
Beta Was this translation helpful? Give feedback.
-
This was just dropped and mentions the policy you asked about I'll release new module version asap to use the 24H2 baselines on systems that run it. |
Beta Was this translation helpful? Give feedback.
This was just dropped and mentions the policy you asked about
https://techcommunity.microsoft.com/t5/microsoft-security-baselines/windows-11-version-24h2-security-baseline/ba-p/4252801
I'll release new module version asap to use the 24H2 baselines on systems that run it.