The Great UAC Debate!


UAC  

1412 members have voted

  1. 1. Do You Use UAC?

    • Yes
      477
    • Yes, On "Silent Mode"
      91
    • No (I use an Admin Account)
      496
    • No (I use a Standard Account)
      39
    • I don't use Windows Vista
      118
  2. 2. Have You Ever Been Saved By UAC?

    • Yes
      226
    • No
      932
    • I don't use Windows Vista
      106


Recommended Posts

It's pretty frustrating when people like you advise others to disable UAC when you don't even understand how it works, or what it's for.

I understand the frustration but I don't want a security advisor asking me what to do. When I give my computer orders, it is to obey them without questions. For example if I want Word on my screen, I want it on my screen, no questions asked.

UAC will not protect 100% because many people are known to be "trigger" happy and will click Yes to every box they get. This will become very common. I know because you remember the IE security warning dialog boxes? Yeah UAC is like that but systemwide. I remember many computers was ridden with spyware and viruses becuse people click Yes to all Security Warning dialogs that disguse the real purpose (to install spyware and viruses disgused as addons or updates).

It's user common sense that play a large role in protecting the computer system from threats.

I understand the frustration but I don't want a security advisor asking me what to do. When I give my computer orders, it is to obey them without questions. For example if I want Word on my screen, I want it on my screen, no questions asked.

UAC will not protect 100% because many people are known to be "trigger" happy and will click Yes to every box they get. This will become very common. I know because you remember the IE security warning dialog boxes? Yeah UAC is like that but systemwide. I remember many computers was ridden with spyware and viruses becuse people click Yes to all Security Warning dialogs that disguse the real purpose (to install spyware and viruses disgused as addons or updates).

It's user common sense that play a large role in protecting the computer system from threats.

Sigh.

UAC can protect you without showing you a single prompt. In fact, that's actually when it's protecting you.

Let's say you launch Word. It is never going to launch itself with Administrative privileges, so it will always be running without access to any element of your filesystem that requires "Administrator" access. Let's say you got an email from a friend, but unbeknownst to you, a crafty little bit of malformed data managed to slip into that document, allowing for arbitrary code execution. Because Word does not have Administrative access to your PC, the amount of damage it can do it very limitted compared to if you had UAC turned off.

Or let's say it's some 0-day exploit in Firefox's JPEG image handler, and you're browsing neowin. The exact same thing as the Word scenario I posed above can happen.

Or even better, let's say you're using IE7. Because the IE process runs with a Low IL, it can't even touch your documents, put a file on your desktop, drop a link in your user startup folder. It just can't do it because the IE process has virtually no real access to your computer. It only can write to the LocalLow folder, where your temporary internet files folder is, and that's going to generally be useless for any exploit's purposes.

UAC is not about second guessing what you're trying to do. What it will do, however, is prevent the machine from automatically allowing a process to spawn another process with greater access to the machine than the original process had. It's simply a tool for controlling how much access to your machine a given process gets when it's launched.

Want a real world example? The ANI exploit was stopped in it's tracks by UAC in many cases.

And that's not even all that UAC does. It also allows for virtualization of the filesystem and registry, to help legacy apps work, and further protect the system by on occasion tricking apps into believing they successfully made changes to areas of the system that they did not have access to, but in actuality storing those changes to an area that only these apps can see.

Edited by MioTheGreat

There's only one reason why I have to turn off UAC, and that is fact that all of the software I develop requires admin permissions, so they bring up a UAC dialog.

- InfoBar freezes without admin permissions due to the possibility that one of it's modules cannot function without them.

- NeoCleaner obviously needs admin privs because it searches for, and deletes, files anywhere on any hard drive that meet certain criteria.

The one thing I really, really, really wish was implemented was a way to check a box and say "Run this application every time with admin privileges." That way apps will run at startup and when I manually start them, without UAC prompts. I think it would be a feature that would make people that turn UAC off happy.

Everywhere here I see people saying that UAC is "great", there is "no reason" to turn it off. Personally I would never use it, but I leave this on for my brother. He always agree with anything that comes up, so there is no point anyway. I guess his antivirus keep he save, so - again - there is no point to UAC.

Has you ever been saved by it? Ever saw the confirmation dialog when you wasn't expecting and actually clicked "cancel"?

No. The information given for some installers is just cryptic and doesn't reflect what the program is, meaning that I often have to allow it even if I'm unsure of the application. That means I could be accepting some random installer that is piggybacking off another application. I like the idea but it becomes so common you don't even look at what is says.

Having said that I haven't disabled it at the moment. I might do at a later stage.

Here is what I think about UAC...

In Vista, when I am doing a fresh, clean install of Vista, I will disable UAC so I can go on installing all my software. Afterwards, I will then turn on UAC for security reasons, and security reasons only.

Here's a little tip: you can try executing your installers from an elevated command prompt window, so you don't actually have to turn it off.

UAC is about as useful as **** on a pump handle

but some people really need this when their mommy and daddy isn't around to ask them if they really 'want to do something'

:wacko:

That's not at all why we have UAC, and it's really terrible to post that kind of stuff, since it's flat out wrong, and people who don't know any better actually come here for advice.

You're at the 'just enough knowledge to be dangerous' level, I believe. You understand how to turn UAC off, and since you don't understand its purpose, you're going to go ahead and do it, because you don't know any better.

Here's why what you just said about hand holding is flat out wrong:

https://www.neowin.net/forum/index.php?show...amp;p=589146941

Edited by Frank
:wacko:

That's not at all why we have UAC, and it's really terrible to post that kind of stuff, since it's flat out wrong, and people who don't know any better actually come here for advice.

You're at the 'just enough knowledge to be dangerous' level, I believe. You understand how to turn UAC off, and since you don't understand its purpose, you're going to go ahead and do it, because you don't know any better.

Here's why what you just said about hand holding is flat out wrong:

https://www.neowin.net/forum/index.php?show...amp;p=589146941

QFT.

UAC doesn't come up very often after the initial installing of software on a fresh install anyway. I have had no problems with it.

Mine is on and it is useful... especially when visiting pron sites :p. I would be browsing a site and UAC would randomly come on asking if this program can be installed. Its obvious that its spyware/worm/virus therefore I cancel.

it is a very nice feature ... but with my PC it's off because some old game can't run with it ^^; ... full screen issues ... but I really like the UAC and I plan to turn it on again :)

but for my family's PCs ... it is a MUST :) ... really saved me from a lot of pain :) ...

i have mine on,if the prompts bother me i use tweakuac to keep it on while having the prompts off,uac is really useful as it helps to protect ie even if you dont use it now thats what i call real immunization.

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • "TeamViewer is the fast, simple and friendly solution for remote access over the Internet" Regarding the "friendly" description, has is stopped unceremoniusly booting your session after a couple of minutes accusing you of using it in a commercial environment?!
    • I hate religious supremacist genocidal maniacs. How antisemitic of you to imply that's what all Jews are like. Still no links I see. I guess when you're a zionists, backing your claims with proof doesn't matter. bEliEvE mE oR yOuRe hItLeR.
    • Moto G Stylus has better specs and a stylus. Search for the specs to see if they they're important to you. 
    • Funny how people who don't use OneDrive feel the need to give their opinion.
    • Win11Debloat 06.10.2026 by Razvan Serea Win11Debloat is a lightweight, easy to use PowerShell script that allows you to quickly declutter and customize your Windows experience. It can remove pre-installed bloatware apps, disable telemetry, remove intrusive interface elements and much more. The script also includes many features that system administrators and power users will enjoy. Such as a powerful command-line interface, support for Windows Audit mode and the option to make changes to other Windows users. All changes made by Win11Debloat can be easily reversed, and most removed apps can be restored via the Microsoft Store. A full guide on how to undo the changes is available here. Win11Debloat features: Below is an overview of the key features and functionality offered by Win11Debloat. Please refer to the wiki for more information about the default settings preset. Remove a wide variety of preinstalled apps. Click here for more info. Disable telemetry, diagnostic data, activity history, app-launch tracking & targeted ads. Disable tips, tricks, suggestions & ads across Windows. Disable Windows location services & app location access. Disable Find My Device location tracking. Disable 'Windows Spotlight' and tips & tricks on the lock screen. Disable 'Windows Spotlight' desktop background option. Disable ads, suggestions and the MSN news feed in Microsoft Edge. Hide Microsoft 365 ads on the Settings 'Home' page, or hide the 'Home' page entirely. Disable & remove Microsoft Copilot. Disable Windows Recall. Disable Click to Do, AI text & image analysis tool. Prevent AI service (WSAIFabricSvc) from starting automatically. Disable AI Features in Edge. Disable AI Features in Paint. Disable AI Features in Notepad. Disable the Drag Tray for sharing & moving files. Restore the old Windows 10 style context menu. Turn off Enhance Pointer Precision, also known as mouse acceleration. Disable the Sticky Keys keyboard shortcut. Disable Storage Sense automatic disk cleanup. Disable fast start-up to ensure a full shutdown. ...and more. Once you’ve downloaded the Win11Debloat file (Get.ps1), just follow these quick steps: Locate the Get.ps1 script file. Right-click the file and select Run with PowerShell from the context menu. If prompted by User Account Control (UAC), select Yes to grant the script the necessary administrative permissions. Win11Debloat 06.10.2026 release notes: This release brings some long-requested features alongside a host of fixes. For starters, Win11Debloat can now automatically detect previously applied tweaks for the logged-in user. And reverting them is as simple as unchecking the corresponding setting. The script now also fully supports running under the SYSTEM account, which has also made it possible to apply changes to users who are still logged in. This makes it far easier to integrate Win11Debloat into your automations and deployments. What's changed: Add confirmation dialogs & warning for Windows Terminal Removal by @Raphire Add Support for running the script under SYSTEM account by @soccerzockt in #609 With this, support was also added for applying changes to users that are still logged-in. Add option to show & undo previously applied tweaks by @Raphire in #599 Add additional options to change the All Apps view in the start menu (Hide, Grid, Category, List) by @Raphire in #599 Clean up logging of exceptions during Appx Package uninstallation via Write-Verbose by @HetCreep in #617 Improve log output in Get.ps1/Get-Dev.ps1 and clean up file exclusions by @Raphire Remove RemoveCommApps and RemoveW11Outlook app removal parameters. Use -RemoveApps parameter instead by @Raphire in #599 Resolve nested quoting bug in Run.bat when path has spaces, see #583 by @Raphire in #599 Fix desync issue when toggling "Only Show Installed" checkbox too fast by @Raphire in #599 Fix: add missing keys in Sysprep/Undo regfiles for Disabling Recall and Windows Suggested content by @Raphire in #599 Fix 'Disable Animations' Sysprep settings not being set for new users by @Raphire in #599 Fix typo in Disable_Game_Bar_Integration Sysprep registry file by @Raphire Note The -RemoveCommApps and -RemoveW11Outlook command-line parameters for uninstalling a few specific apps have been removed with this release. If you previously relied on these parameters, please see this wiki page for alternative methods of removing these apps. Download: Win11Debloat 06.10.2026 | Open Source View: Win11Debloat Home Page | Screenshots 1| 2 Get alerted to all of our Software updates on Twitter at @NeowinSoftware
  • Recent Achievements

    • One Month Later
      Sopa flores earned a badge
      One Month Later
    • First Post
      StaticMatrix earned a badge
      First Post
    • Week One Done
      StaticMatrix earned a badge
      Week One Done
    • Rookie
      lamborghiniv10 went up a rank
      Rookie
    • One Month Later
      pinnclepd earned a badge
      One Month Later
  • Popular Contributors

    1. 1
      +primortal
      508
    2. 2
      PsYcHoKiLLa
      207
    3. 3
      +Edouard
      156
    4. 4
      Steven P.
      89
    5. 5
      ATLien_0
      79
  • Tell a friend

    Love Neowin? Tell a friend!