Group Policy Settings for User Account Control
October 4th, 2010 by Paul Sterley | No Comments | Filed in Management Software, Workstation OSUAC settings can be enforced via group policy in the following area:
Computer Configuration -> Policuies -> Windows Settings -> Security Settings -> Local Policies -> Security Options.
Below are the settings that simulate the 4 options on the slider bar in the GUI.
This information was submitted by Ronnie Vernon MVP, in this thread.
I am re-posting it here mainly for my own convenience in finding it again later.
Commenters on the thread report that the settings go into effect on the workstation, but do not affect the ability of the user to move the slider bar. It will move, the user will be prompted for a reboot, and the setting will be changed when they finish rebooting. Then it will be reset back to the GPO settings at the next GPO processing interval.
When I attempted to follow these directions, I found that the settings available to me in SBS 2008 were slightly different. I did not have an option for “Behavior of the elevation prompt for administrators in Admin Approval Mode = Prompt for consent for non-Windows binaries”. The closest thing was “Behavior of the elevation prompt for administrators in Admin Approval Mode = Prompt for consent”, which set the slider at Level 4. I looked for administrative templates to update this, and did not find anything. I guess level 4 will have to do for now.
***
Admin Approval Mode for the Built-in Administrator account = Disabled
Allow UIAccess applications to prompt for elevation without using the secure desktop = Disabled
Behavior of the elevation prompt for administrators in Admin Approval Mode = Elevate without prompting
Behavior of the elevation prompt for standard users = Prompt for credentials
Detect application installations and prompt for elevation = Enabled
Only elevate executables that are signed and validated = Disabled
Only elevate UIAccess applications that are installed in secure locations = Enabled
Run all administrators in Admin Approval Mode = Disabled
Switch to the secure desktop when prompting for elevation = Disabled
Virtualize file and registry write failures to per-user locations = Enabled
———————————————
***
Admin Approval Mode for the Built-in Administrator account = Disabled
Allow UIAccess applications to prompt for elevation without using the secure desktop = Disabled
Behavior of the elevation prompt for administrators in Admin Approval Mode = Prompt for consent for non-Windows binaries
Behavior of the elevation prompt for standard users = Prompt for credentials
Detect application installations and prompt for elevation = Enabled
Only elevate executables that are signed and validated = Disabled
Only elevate UIAccess applications that are installed in secure locations = Enabled
Run all administrators in Admin Approval Mode = Enabled
Switch to the secure desktop when prompting for elevation = Disabled
Virtualize file and registry write failures to per-user locations = Enabled
——————————————-
***
Admin Approval Mode for the Built-in Administrator account = Disabled
Allow UIAccess applications to prompt for elevation without using the secure desktop = Disabled
Behavior of the elevation prompt for administrators in Admin Approval Mode = Prompt for consent for non-Windows binaries
Behavior of the elevation prompt for standard users = Prompt for credentials
Detect application installations and prompt for elevation = Enabled
Only elevate executables that are signed and validated = Disabled
Only elevate UIAccess applications that are installed in secure locations = Enabled
Run all administrators in Admin Approval Mode = Enabled
Switch to the secure desktop when prompting for elevation = Enabled
Virtualize file and registry write failures to per-user locations = Enabled
————————————————
***
Admin Approval Mode for the Built-in Administrator account = Disabled
Allow UIAccess applications to prompt for elevation without using the secure desktop = Disabled
Behavior of the elevation prompt for administrators in Admin Approval Mode = Prompt for consent on the secure desktop
Behavior of the elevation prompt for standard users = Prompt for credentials
Detect application installations and prompt for elevation = Enabled
Only elevate executables that are signed and validated = Disabled
Only elevate UIAccess applications that are installed in secure locations = Enabled
Run all administrators in Admin Approval Mode = Enabled
Switch to the secure desktop when prompting for elevation = Enabled
Virtualize file and registry write failures to per-user locations = Enabled
Tags: GPO, Group Policy, UAC, User Account Control

