Just a quick question for all the Security experts out here regarding the new Administrator Protection feature on Windows 11.
From the Group Policy settings, which one would be the more secure setting?
User Account Control: Behavior of the elevation prompt for administrators running with Administrator protection >>> Prompt for Consent on the Secure Desktop
Or
Prompt for Credentials on the Secure Desktop?
The reason why I am asking because suppose a malware might compromise a system and may capture the account credential password or the Windows Hello PIN using a keystroke logger.
So in that case or scenario, would a setting of Prompt for Consent on the Secure Desktop be more secure just by clicking Yes/No from the prompt?
My standalone Windows machine is running as a local Admin account using a Windows Hello PIN.
I also do not reuse passwords.
From the Group Policy settings, which one would be the more secure setting?
User Account Control: Behavior of the elevation prompt for administrators running with Administrator protection >>> Prompt for Consent on the Secure Desktop
Or
Prompt for Credentials on the Secure Desktop?
The reason why I am asking because suppose a malware might compromise a system and may capture the account credential password or the Windows Hello PIN using a keystroke logger.
So in that case or scenario, would a setting of Prompt for Consent on the Secure Desktop be more secure just by clicking Yes/No from the prompt?
My standalone Windows machine is running as a local Admin account using a Windows Hello PIN.
I also do not reuse passwords.
Last edited:




