Administrator Protection recommended settings?


Just a quick question for all the Security experts out here regarding the new Administrator Protection feature on Windows 11.

From the Group Policy settings, which one would be the more secure setting?

User Account Control: Behavior of the elevation prompt for administrators running with Administrator protection >>> Prompt for Consent on the Secure Desktop

Or

Prompt for Credentials on the Secure Desktop?


The reason why I am asking because suppose a malware might compromise a system and may capture the account credential password or the Windows Hello PIN using a keystroke logger.

So in that case or scenario, would a setting of Prompt for Consent on the Secure Desktop be more secure just by clicking Yes/No from the prompt?

My standalone Windows machine is running as a local Admin account using a Windows Hello PIN.

I also do not reuse passwords.
 
Last edited:
No documentation mentions anything at any other time other than changing the UAC popup a bit (with support for PIN/biometrics) and the elevated process uses a different, on the fly account different from the original one. Again, nice, but not a gamechanger, just an improvement over the default UAC settings.

Not coincidentally, this is pretty much the same as using the normal UAC with a standard account elevating to a different admin account using a password, a feature available since Vista.
 

My Computer My Computer

At a glance

Windows 11
OS
Windows 11
Computer type
PC/Desktop

My Computer My Computer

At a glance

Windows 11
OS
Windows 11
Computer type
Laptop

Latest Support Threads

Back
Top Bottom