User Account Control: Admin Approval Mode for the Built-in Administrator accountID: oval:org.secpod.oval:def:8842 | Date: (C)2013-01-21 (M)2023-05-09 |
Class: COMPLIANCE | Family: windows |
The User Account Control: Admin Approval Mode for the Built-in Administrator account setting should be configured correctly.
This policy setting controls the behavior of Admin Approval Mode for the built-in Administrator account. The options are: * Enabled: The built-in Administrator account uses Admin Approval Mode. By default, any operation that requires elevation of privilege will prompt the user to approve the operation. * Disabled: (Default) The built-in Administrator account runs all applications with full administrative privilege.
Fix:
(1) GPO: Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options\User Account Control: Admin Approval Mode for the Built-in Administrator account
(2) KEY: HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System\FilterAdministratorToken
Platform: |
Microsoft Windows Server 2008 R2 |