How to remove UAC shield icon from shortcuts when UAC is disabled?


Recommended Posts

There are countless articles online on how to remove the UAC shield icon from shortcuts and absolutely none of them work.  

I run Windows 11 with UAC disabled.  I do not need nor want it.  But I also have several of my Desktop shortcuts set to "run as admin".  

Is there an actual working  way to get rid of them, they are quite annoying and make my icons look like ######.  

Deleting the cache won't work because I don't want to remove "run as admin", the shield icon just comes back.  

Is it possible to get rid of these ugly shields without enabling UAC or removing "run as admin"?  

Not to mention that clearing the cache doesn't seem to be truly possible because even in safe mode the files in users\*username*\appdata\local\microsoft\windows\explorer that are named with "iconcache" are always in use so even via command prompt you can't truly delete them.  Annoying.  AF.  

You can't do that easily, because behind the scenes, you can't actually turn off UAC. What the "Never notify" setting of the User Account Control Settings does is, as it says, is to never notify you when a program is launched with elevated privileges. But the principle of least-privilege remains. If you remove the shield icon, you won't have any way of knowing that a specific program or shortcut will be launched using elevated privileges. That's a security risk.

There might be a way to remove the shield (that is technically an Explorer overlay icon), but it seems that, for the shield icon, Microsoft has implemented some changes in the latest updates to disallow removing that specific overlay. Say you find a working workaround: it might be not stick because a future update will revert the change.

If you really don't want the shield overlay for a given icon on your Desktop, a better workaround would be to:

  1. Create a .bat to launch the desired program (so the .bat won't run elevated, but the program launched by the .bat will)
  2. Make a shortcut to this .bat, and then
  3. Customize the shortcut's icon so that it has the launched program's icon

There is a how-to here.

Edited by Newinko
  • Like 1

Doesn't Winaero Tweaker have a setting to remove them? 

I won't comment on the foolishness of trying to turn off a feature that literally keeps someone from ruining your computer.

The other option?  Don't have shortcuts to apps on your Desktop.  I will never understand why some folks insist on shortcuts on their desktop.  

  • Like 5
On 21/09/2023 at 07:26, devHead said:

I won't comment on the foolishness of trying to turn off a feature that literally keeps someone from ruining your computer.

You keep saying that but it is user choice, you are not entitled to demerit, just because you say so, somebody's choice on how they want windows to be handled.

 

On 21/09/2023 at 09:48, Arceles said:

You keep saying that but it is user choice, you are not entitled to demerit, just because you say so, somebody's choice on how they want windows to be handled.

 

Who is saying it's not an user choice? One can certainly comment that something is not a good security practice. You should not assume the OP has any idea what they are doing.  The fact they thought they "disabled" UAC (when didn't) and stated they don't need it suggests they do not.

On 21/09/2023 at 09:52, Good Bot, Bad Bot said:

Who is saying it's not an user choice? One can certainly comment that something is not a good security practice. You should not assume the OP has any idea what they are doing.  The fact they thought they "disabled" UAC (when didn't) and stated they don't need it suggests they do not.

You can warn but not demerit because for the latter you are also assuming the user understanding of what it is doing.

A trick that I use is to run programs that need UAC elevation through the Windows Task Scheduler.  I create a task that starts a program that needs elevation.  I make sure to select to "Run with highest privileges" and "Allow task to be run on demand".  Then I create a shortcut to run that task, like:
C:\Windows\System32\schtasks.exe /Run /TN "The exact name of the task you just created"

That shortcut will have the command prompt icon by default, but you just right-click and "change icon" and point to the executable of the program in the task to select that icon.  You can also rename the shortcut to the name of the program.  That shortcut will now launch without a UAC popup and no shield on the icon.  Plus, UAC is still running at the default level theoretically protecting you a little.

 

edit: I forgot that I also select to "run minimized" so I don't see the command prompt when the shortcut is used.  So far all of my programs still pop up normally.

On 21/09/2023 at 06:48, Arceles said:

You keep saying that but it is user choice, you are not entitled to demerit, just because you say so, somebody's choice on how they want windows to be handled.

 

I can demerit.  The default is to protect the user. He doesn't want to be protected or think he needs to be.  I have an opinion that is different from his, and mine is the right one, because it's the one that protects my computer.  You're right, he can do whatever he wants and do not care if he wants to.  But I can demerit him. 

On 21/09/2023 at 21:26, devHead said:

I can demerit.  The default is to protect the user. He doesn't want to be protected or think he needs to be.  I have an opinion that is different from his, and mine is the right one, because it's the one that protects my computer.  You're right, he can do whatever he wants and do not care if he wants to.  But I can demerit him. 

To be fair, it's not even demeriting. You're just stating the facts.

On 21/09/2023 at 22:26, devHead said:

I can demerit.  The default is to protect the user. He doesn't want to be protected or think he needs to be.  I have an opinion that is different from his, and mine is the right one, because it's the one that protects my computer.  You're right, he can do whatever he wants and do not care if he wants to.  But I can demerit him. 

Suuuuure, just because you say so. Sere is a uno reverse card for you, if you really wanted to be secure you would not be using windows and since it is *my opinion* is the correct one. Typical.

  • Facepalm 3
On 22/09/2023 at 12:41, Arceles said:

Suuuuure, just because you say so. Sere is a uno reverse card for you, if you really wanted to be secure you would not be using windows and since it is *my opinion* is the correct one. Typical.

In the past that may have been true, but it's due more to obscurity not actual security.

 

macOS has vulnerabilities.
iOS has vulnerabilities.
Android has vulnerabilities (arguably more than iOS).
Windows has vulnerabilities.
Linux has vulnerabilities.
BSD has vulnerabilities.

 

UAC is the graphical equivalent of the sudo command on *nix, as such it should never be bypassed if you want to keep good security practices. 

On 22/09/2023 at 10:54, Matthew S. said:

In the past that may have been true, but it's due more to obscurity not actual security.

 

macOS has vulnerabilities.
iOS has vulnerabilities.
Android has vulnerabilities (arguably more than iOS).
Windows has vulnerabilities.
Linux has vulnerabilities.
BSD has vulnerabilities.

 

UAC is the graphical equivalent of the sudo command on *nix, as such it should never be bypassed if you want to keep good security practices. 

Every single OS has vulnerabilities... but then again, whose servers are most of the stuff being run on? Linux. And if there are vulnerabilities to be addressed is exactly there.

What's the point of running something as an administrator if you are an administrator and you have user account control disabled? Wouldn't that just run it in the security context of your current user?

On 22/09/2023 at 09:41, Arceles said:

Suuuuure, just because you say so. Sere is a uno reverse card for you, if you really wanted to be secure you would not be using windows and since it is *my opinion* is the correct one. Typical.

Problem is when you try to use opinion to defeat fact.

 

Fact always wins.

On 22/09/2023 at 22:07, DewThePDX said:

Problem is when you try to use opinion to defeat fact.

 

Fact always wins.

That is cute, therefore, you can demerit because of facts instead of using facts to advise of the dangers of having a particular setting being removed... not surprised really.

On 22/09/2023 at 21:44, Arceles said:

That is cute, therefore, you can demerit because of facts instead of using facts to advise of the dangers of having a particular setting being removed... not surprised really.

You keep using that word, 'demerit'.  I don't think it means what you think it means.

  • Like 1
  • Haha 1
On 23/09/2023 at 07:48, devHead said:

You keep using that word, 'demerit'.  I don't think it means what you think it means.

Way too late for you to say that.

On 24/09/2023 at 00:26, DewThePDX said:

It's really not.

All I'm seeing here is a pile of logical fallacies in search of a dopamine hit.

Cool, the only fallacy I see here is how a bunch of people that believe themselves security experts think that everything should be one way, the windows way and I seriously disagree with it.

On 24/09/2023 at 07:14, Arceles said:

Cool, the only fallacy I see here is how a bunch of people that believe themselves security experts think that everything should be one way, the windows way and I seriously disagree with it.

A bunch of people who think that the way Windows helps protect your PC is the correct way.  We're not security experts, but I would say that someone who wants to disable a security feature is also NOT a security expert.  Plus, it doesn't matter whether you agree with the way Windows handles security for the PC - heck, you're not even running Windows according to your signature.  So who are you to keep posting here and trying to correct others?  A fallacy means that something is false.  Are you saying that it's false to assume that having UAC enabled helps keep a PC more secure than when it's completely disabled?  Try running everything in Debian as root.  Would you do that? 

On 24/09/2023 at 08:44, devHead said:

A bunch of people who think that the way Windows helps protect your PC is the correct way.  We're not security experts, but I would say that someone who wants to disable a security feature is also NOT a security expert.  Plus, it doesn't matter whether you agree with the way Windows handles security for the PC - heck, you're not even running Windows according to your signature.  So who are you to keep posting here and trying to correct others?  A fallacy means that something is false.  Are you saying that it's false to assume that having UAC enabled helps keep a PC more secure than when it's completely disabled?  Try running everything in Debian as root.  Would you do that? 

Because you simply do not know and your assumptions are making you look rather silly. Sure I do not for the most part use windows, but I have to use it in my ROG ALLY because Linux is not supported there yet. And I have been using windows even prior it had a GUI for it to know how the entire PC landscape, as well as security, works and that is why I switched to Linux after Window 11 came in. TRUE, you expose yourself to dangers whenever setting administrator rights to everything and this is a problem for the user that does not know anything and handle such PC as a normal everyday use one, but that does not mean that such case has an use, for example, in offline PCs and or legacy applications.

The absolute view of the people that things should be handled one way here is just baffling, unable to accept that there are reasons to do stuff out of the conventional way, quite akin to fascism.

On 24/09/2023 at 07:50, Arceles said:

Because you simply do not know and your assumptions are making you look rather silly. Sure I do not for the most part use windows, but I have to use it in my ROG ALLY because Linux is not supported there yet. And I have been using windows even prior it had a GUI for it to know how the entire PC landscape, as well as security, works and that is why I switched to Linux after Window 11 came in. TRUE, you expose yourself to dangers whenever setting administrator rights to everything and this is a problem for the user that does not know anything and handle such PC as a normal everyday use one, but that does not mean that such case has an use, for example, in offline PCs and or legacy applications.

The absolute view of the people that things should be handled one way here is just baffling, unable to accept that there are reasons to do stuff out of the conventional way, quite akin to fascism.

Fascism?  What are you smoking bro?  The OP is not using Windows 11 for offline or legacy usage.  I'm talking in general about how UAC protects your PC. You're right; I don't know his use case, but I know that any computer with UAC enabled is generally more secure than without it.  

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • llamas are unruly going haywire in New Guinea.
    • The Persuasion Engine: How Any Business Can Use AI-Powered Neuromarketing —was $28 now free by Steven Parker Claim your complimentary copy (worth $35) of "The Persuasion Engine: How Any Business Can Use AI-Powered Neuromarketing to Understand and Win Customers" for free, before the offer ends on June 24. Description The Persuasion Engine, by neuromarketing and behavioral science expert Roger Dooley, solves the most pressing challenge faced by every marketer: how to figure out why customers make the decisions they do when 95% of their thought processes occur at an unconscious level. Dooley explains how artificial intelligence democratizes sophisticated neuromarketing tools that were once available only to Fortune 500 companies, making powerful customer insight and persuasion techniques accessible to businesses of any size. The book walks you through the evolution of traditional neuromarketing into ”Neuromarketing 2.0,” where AI-powered tools eliminate the need for expensive lab studies and human behavioral science experts. It offers a comprehensive roadmap for implementing eye tracking, facial coding, biometrics, implicit testing, and advanced AI behavioral techniques that dramatically improve marketing effectiveness while reducing costs and time investment. Inside the book, you’ll find: Revolutionary AI prompting strategies that bring world-class behavioral science expertise to your desktop Practical frameworks for leveraging attention, emotion, credibility, and decision architecture to boost conversions Step-by-step guidance for implementing biometric tools and implicit testing without laboratory resources Advanced techniques for creating scarcity, urgency, and FOMO that drive immediate customer action Comprehensive methods for auditing and enhancing empathy in customer communications Perfect for marketing professionals, business owners, entrepreneurs, and anyone with a stake in customer acquisition and retention, The Persuasion Engine provides actionable strategies that will transform your approach to marketing. Whether you're working on a shoestring or managing enterprise campaigns, you'll discover how to use your customers' non-conscious motivations and create compelling marketing that work on real people in the real world. How to download for free Please ensure you read the terms and conditions to claim this offer. Complete and verifiable information is required in order to receive this free offer. If you have previously made use of these offers, you will not need to re-register. Was $28, but is now FREE | Below free offer link expires on June 24. The Persuasion Engine: How Any Business Can Use AI-Powered Neuromarketing to Understand and Win Customers The below offers are also available for free in exchange for your (work) email: The Vibe Coding Playbook: Building Your Tech Business with AI ($35 Value) FREE - Expires 6/23 The Persuasion Engine: How Any Business Can Use AI-Powered Neuromarketing to Understand and Win Customers ($28 Value) FREE - Expires 6/24 How to Do More with Less: Future-Proofing Yourself in an AI-driven Economy ($28 Value) FREE - Expires 6/30 Cloud Security Fundamentals: Building the Foundations for Secure Cloud Platforms ($131.95 Value) FREE - Expires 7/1 The Complete Free AI Learning: Master ChatGPT, Claude, Gemini & More ($21 Value) FREE How to Build an AI Design Workflow with Gamma ($21 Value) FREE The Ultimate Linux Newbie Guide – Featured Free content Python Notes for Professionals – Featured Free content Learn Linux in 5 Days – Featured Free content Quick Reference Guide for Cybersecurity – Featured Free content We post these because we earn commission on each lead so as not to rely solely on advertising, which many of our readers block. It all helps toward paying staff reporters, servers and hosting costs. Other ways to support Neowin The above deal not doing it for you, but still want to help? Check out the links below. Check out our partner software in the Neowin Store Buy a T-shirt at Neowin's Threadsquad Subscribe to Neowin - for $14 a year, or $28 a year for an ad-free experience Disclosure: An account at Neowin Deals is required to participate in any deals powered by our affiliate, StackCommerce. For a full description of StackCommerce's privacy guidelines, go here. Neowin benefits from shared revenue of each sale made through the branded deals site.
    • All versions is correct. The bug appears on any version of Windows with KB5094126 installed. It's a little insane to expect the author to explain that systems that can't possibly have that patch installed, will not experience the bug. If you have any gripe about the title, it would be that it doesn't mention the update at all, but I wouldn't agree with that either. A title is not expected to be a full summery of the article.
    • (Can't see if he's still wearing the clompy clown shoes though)
    • I'd say the first one failed to be as popular as Apple anticipated, but the easy adjustment here is to make fewer of them next time around. It would only be a "flop" if it isn't possible for Apple to recover the design and factory tooling costs given the number of units sold, which I doubt would be the case. It isn't like no one bought them; it just failed to become the new hot phone of the year.
  • Recent Achievements

    • Week One Done
      Eurosoft10 earned a badge
      Week One Done
    • One Month Later
      Eurosoft10 earned a badge
      One Month Later
    • One Year In
      Skeet Campbell earned a badge
      One Year In
    • One Month Later
      Sharbel earned a badge
      One Month Later
    • First Post
      BizSAR earned a badge
      First Post
  • Popular Contributors

    1. 1
      +primortal
      589
    2. 2
      +Edouard
      190
    3. 3
      Michael Scrip
      76
    4. 4
      PsYcHoKiLLa
      75
    5. 5
      neufuse
      73
  • Tell a friend

    Love Neowin? Tell a friend!