Make your Vista's admin account acts like in XP


Recommended Posts

First let me start by saying that one of the main features of Windows Vista is the new user accounts security enhancements, but sometimes, defaults don't meet everyone's taste when it comes to how we deal with our PCs. I for one, always used full administrator accounts since I first knew what a Windows user account is, and never been hit by a virus/spyware/crap, using common sense and updated AV software, so I don't want to give permissions to myself or face strange error messages every time I do a simple task on my computer.

We know UAC feature in Windows Vista, and we all know how to disable it, this is not the purpose of this thread, because even after you disable UAC, you'll have other prompts about folder/file permissions errors sometimes (I faced it in strange, unexpected occasions, like deleting an empty folder for a program left by the uninstaller), or you'll need to right click and select "Run as Administrator" for most applications to work/install correctly.

That's because Microsoft made the administrators accounts (in local administrators group) run as standard users, unless we give permissions for every and each administrative tasks, with a little difference when UAC is turned on/off

Enough introductions, lets get our hands dirty:

*************************************

Remember that cute "Administrator" account you see when you login to safe mode in XP? That's the built-in administrator account that's installed by default, and disabled by default too, after a little digging-in I made this tutorial that'll let you enable and use this account in normal mode, and with a little other tweak, enjoying an XP-like administrator experience, while UAC is left ON (or off, it doesn't matter), but with no prompts or right clicks.

For Windows Vista Ultimate/Business/Enterprise:

1- Click Start, and type "secpol.msc" in the search area and click Enter. (You may receive a prompt from UAC, approve/login and proceed)

2- In the left list, choose "Local Policies", then "Security Options"

3- Set "Accounts: Administrator account status" to Enabled.

4- Set "User Account Control: Admin Approval Mode for the Built-in Administrator account" to Disabled.

For Windows Vista Home Basic/Home Premium:

1- Click Start, and type "cmd" in the search area, right click on "Command Prompt" and select 'Run as Administrator".

2- In the command prompt type "net users Administrator /active:yes" (Note the capital "A" in Administrator) and press Enter, you will get a confirmation as "The command completed successfully".

3- Click Start, and type "regedit" in the search area and click Enter, navigate to: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System]

Double click on "FilterAdministratorToken" and set it to ""

*************************************

Now log-off, and you'll see new account named "Administrator" is available, click on it to login.

Now you are the master of your domain! I recommend if you're going to use this method is to apply it as soon as you do a fresh install of Windows, so you can simply delete whatever administrator you've created in the setup process, and make this one the "real" administrator for your PC, also you can rename this new admin account or change its password like any other account from "User Accounts" in the Control Panel.

A last note/disclaimer:

Please note that disabling UAC and using the built in Adminstrator account will also disable IE7 "Protected Mode", fore more information and a work around please see this post.

Please apply this procedures only if you know what you're doing. Disabling security features in the operating system is not something recommended to the average Joe, and for sure I won't be held accountable for any damaging happens to your system or files resulting from running a full administrator account all the time.

Enjoy! :)

Special thanks to:

- Farstrider for providing the location of the relevant register keys that made applying this method to the home versions of Vista possible!.

- bradavon for his comment/solution of IE7 protected mode.

Edited by Tantawi
the built in admin account, iirc, has some perms that your normal admins dont, but it also lacks some perms that your normal admins do. at least in XP it was like this....anyone confirm?

By default the administrator account does not have permission to access the files of other users if the others users are configured to make their files private (I'm basing this on my domain controller setup but I believe its the same for local accounts)

But as an administrator, you can take ownership of the files and then change the permissions.

And of course if other users encrypt their files then the admin account can't access them.

Vista appears to be the same.

You can also use gpedit.msc

secpol.msc's items are a subset of gpedit.msc

You can also adjust the settings in the registry here:

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Policies\System]

These are the main keys that affect UAC, equivalent to the secpol.msc

settings.

"ConsentPromptBehaviorAdmin"

"ConsentPromptBehaviorUser"

"EnableInstallerDetection"

"EnableLUA"

"EnableSecureUIAPaths"

"EnableVirtualization"

"PromptOnSecureDesktop"

"ValidateAdminCodeSignatures"

"FilterAdministratorToken"

You can also use gpedit.msc

secpol.msc's items are a subset of gpedit.msc

You can also adjust the settings in the registry here:

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Policies\System]

These are the main keys that affect UAC, equivalent to the secpol.msc

settings.

"ConsentPromptBehaviorAdmin"

"ConsentPromptBehaviorUser"

"EnableInstallerDetection"

"EnableLUA"

"EnableSecureUIAPaths"

"EnableVirtualization"

"PromptOnSecureDesktop"

"ValidateAdminCodeSignatures"

"FilterAdministratorToken"

maybe someone could post some reg tweaks for the above keys, so that we can just copy and paste them into notepad and save them as .reg files, would be very handy:)!

Nice work, but why would someone use the Administrator account?

I've just turned off UAC and have my own user with Administrator privileges.

That was even less work then this solution...

because of some popup messages and some programs wont even run like the bios flash utility for my hp laptop, it wont even work when you choose "run as administrator".

Suppose i use this method. I currently don't have to log onto my computer, it just boots to windows. After doing this change will i be prompted choose a user to log in with as there would be 2 users and i would then have to log in?

If it does create a log in after i deleate the old admin account will the log in process go away (assuming that i don't use a password for the new admin)?

Suppose i use this method. I currently don't have to log onto my computer, it just boots to windows. After doing this change will i be prompted choose a user to log in with as there would be 2 users and i would then have to log in?

If it does create a log in after i deleate the old admin account will the log in process go away (assuming that i don't use a password for the new admin)?

Yes, that's why I recommend to do it as soon as you install a fresh window so you don't be worried about deleting the admin account you created in the setup process :) After you delete it, you'll login automatically as long as you don't set a password of course.

You can also use gpedit.msc

secpol.msc's items are a subset of gpedit.msc

You can also adjust the settings in the registry here:

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Policies\System]

These are the main keys that affect UAC, equivalent to the secpol.msc

settings.

"ConsentPromptBehaviorAdmin"

"ConsentPromptBehaviorUser"

"EnableInstallerDetection"

"EnableLUA"

"EnableSecureUIAPaths"

"EnableVirtualization"

"PromptOnSecureDesktop"

"ValidateAdminCodeSignatures"

"FilterAdministratorToken"

Nice guide,but I can only access to this settings via registry in vista home basic.

I like to ask which one number we must past here in this lines?

), or you'll need to right click and select "Run as Administrator" for most applications to work/install correctly.

That makes absolutely no sense. There's no split token when you disable UAC via that dialog. The "Run As Administrator" option should have no effect at all.

The only time you'd have to do that would be if you disable UAC by setting admins to auto-elevate (as I suggested in another thread).

@ Brandon Live

I'm curious to know your opinion on:

Remember that cute "Administrator" account you see when you login to safe mode? That's the built-in administrator account that's installed by default, and disabled by default too, after a little digging-in I made this tutorial that'll let you enable and use this account in normal mode, and with a little other tweak, enjoying an XP-like administrator experience, while UAC is left ON (or off, it doesn't matter), but with no prompts or right clicks.

1- Click Start, and type "secpol.msc" in the search area and click Enter.

2- You may receive a prompt from UAC, approve/login and proceed.

3- In the left list, choose "Local Policies", then "Security Options"

4- Set "Accounts: Administrator account status" to Enabled.

5- Set "User Account Control: Admin Approval Mode for the Built-in Administrator account" to Disabled.

6- Now log-off, and you'll see a new account named "Administrator" will be available, click on it to login.

Now you are the master of your domain! I recommend if you're going to use this method is to apply it as soon as you do a fresh install of Windows, so you can simply delete whatever administrator you created in the setup process, and make this one the "real" administrator for your PC, also you can rename this new admin account or change its password like any other account from "User Accounts" in the Control Panel.

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Speaking of right, right dominant only which, as with most, makes this meaningless to me.
    • No, size is not the only selling point. I did not even remotely say that. Your claim was that "building your own will be faster and cheaper". This is false. You cannot build something close to that form factor with off-the-shelf parts. You can build a Mini-ITX PC and pay more, or something larger and pay less. But these are different market segments. It's apples and oranges.
    • There is a default resolution setting in Settings > Display that can be changed with a click. You can also change the settings on a per-game basis. No CLI needed. Also, Steam has countless games that are not "[perpetual] alpha/beta games", so no need for the straw man. Plus you can use other stores as well. And console games (e.g. PS5) cost a fortune, which itself more than negates the price subsidy on the system, unless you plan on exclusively playing 1 or 2 games. It's true that you shouldn't buy a system that doesn't support the game(s) you want to play, but I think that's kinda obvious, and applies to every console as well as PC. I don't game in the living room and have no need of a Steam Machine, but there is a clear market segment that would find it useful.
    • RSS Guard 5.2.0 by Razvan Serea RSS Guard is a simple (yet powerful) feed reader. It is able to fetch the most known feed formats, including RSS/RDF and ATOM. It's free, it's open-source. RSS Guard currently supports Czech, Dutch, English, French, German, Italian. RSS Guard will never depend on other services - this includes online news aggregators like Feedly, The Old Reader and others. RSS Guard is developed on top of the Qt library and it supports these operating systems: Windows GNU/Linux OS/2 (eComStation) Mac OS X xBSD (possibly) Android (possibly) other platforms supported by Qt The core features of RSS Guard are: support for online feed synchronization via plugins, Tiny Tiny RSS (from RSS Guard 3.0.0). multiplatform, support for all feed formats, simplicity, import/export of feeds to/from OPML 2.0, downloader with own tab and support for up to 6 parallel downloads, message filter with regular expressions, feed metadata fetching including icons, simple Adblock functionality, customized popup notifications, Google-based auto-completion for internal web browser location bar, ability to cleanup internal message database with various options, enhanced feed auto-updating with separate time intervals, multiple data backend support, SQLite (in-memory DBs too), MySQL. is able to specify target database by its name (MySQL backend), “portable” mode support with clever auto-detection, feed categorization, drap-n-drop for feed list, automatic checking for updates, ability to discover existing feeds on websites, full support of podcasts (both RSS & ATOM), ability to backup/restore database or settings, fully-featured recycle bin, printing of messages and any web pages, can be fully controlled via keyboard, feed authentication (Digest-MD5, BASIC, NTLM-2), handles tons of messages & feeds, sweet look & feel, fully adjustable toolbars (changeable buttons and style), ability to check for updates on all platforms + self-updating on Windows, hideable main menu, toolbars and list headers, KFeanza-based default icon theme + ability to create your own icon themes, fully skinnable user interface + ability to create your own skins, “newspaper” view, plenty of skins, support for "feed://" URI scheme, ability to hide list of feeds/categories, open-source development model based on GNU GPL license, version 3, tabbed interface, integrated web browser with adjustable behavior + external browser support, internal web browser mouse gestures support, desktop integration via tray icon, localizations to some languages, Qt library is the only dependency, open-source development model and friendly author waiting for your feedback, no ads, no hidden costs. RSS Guard 5.2.0 changelog: Added: Feed auto-fetch can now also be delayed while Feral GameMode is active on Linux and startup auto-fetch is skipped when GameMode is already active. (#2265) WebEngine builds can now use RSS Guard generated proxy auto-config (PAC) rules so article/web browsing follows per-account and per-feed proxy settings more closely. (#2273) Generated PAC rules now also cover related subdomains and use Public Suffix List data, so feeds such as feeds.bbc.co.uk can also proxy resources from images.bbc.co.uk. (#2273) Standard feeds can now define extra proxy domains, useful when article images, stylesheets or other page resources are loaded from a CDN or another domain that should use the same feed proxy. (#2273) RSS Guard now asks for proxy credentials when a WebEngine page needs proxy authentication and can fill credentials from the current feed proxy when available. (#2273) Network settings again include an option to ignore all cookies, which clears stored cookies and prevents new cookies from being accepted. Standard RSS/ATOM feeds can now individually ignore cookies while downloading feed data. Stored cookies can now be deleted from the Tools menu. Custom skin colors can now override the feed list article count color separately from feed titles, including a separate highlighted color. (#2275) Settings dialog can now search across available settings and highlight matching controls. (#1754) Standard RSS/ATOM feeds can now optionally be reported as broken when they are valid but contain no articles. (#2039) Standard RSS/ATOM feeds can now override the application-wide feed connection timeout per feed. (#1023) Tray icon can now use a custom background color and unread-count text color, with an option to reuse the generated icon as the application icon. (#1973) Support for more benevolent parsing of Gemlog entries (#2295). Article list can now show when an article was received by RSS Guard. (#947) Feed deep discovery now actually scrapes all links found in the website and checks if they are feeds or not. This greatly enhances usability of the deep discovery mode and discovers many more feeds than before. (#2306) Search boxes now show a small dot when the feed or article list is hiding some items because of active filtering. (#873) Articles now have a shortcut-assignable action to open the homepage of the feed they belong to. (#2060) Fixed: Parallel feed updates no longer crash when multiple update results are processed at the same time. (64cf521) Links in WebEngine articles opened from feeds such as Kill the Newsletter now open correctly instead of being swallowed by the embedded page. (#2272) Relative article URLs resolution was kinda broken. (#2282) Clicking article URL did not work when the URL had "fragment" set. (#2293) The default proxy setting now uses Qt/system default proxy behavior instead of forcing no proxy. (e0263ad) WebEngine article loading now keeps the current feed context, so feed-specific proxy credentials remain available while the article page loads. (fdd0f00) Download: RSS Guard 5.2.0 (64-bit) | Portable | ~ 130.0 MB (Open Source) Link: RSS Guard Home Page | Other Operating Systems | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
  • Recent Achievements

    • Rookie
      DaviKar went up a rank
      Rookie
    • Dedicated
      HidekoYamamoto94 earned a badge
      Dedicated
    • One Month Later
      timbobit earned a badge
      One Month Later
    • One Month Later
      nates earned a badge
      One Month Later
    • Week One Done
      Almohandis earned a badge
      Week One Done
  • Popular Contributors

    1. 1
      +primortal
      461
    2. 2
      +Edouard
      161
    3. 3
      PsYcHoKiLLa
      110
    4. 4
      Michael Scrip
      83
    5. 5
      Steven P.
      69
  • Tell a friend

    Love Neowin? Tell a friend!