The Great UAC Debate!


UAC  

1412 members have voted

  1. 1. Do You Use UAC?

    • Yes
      477
    • Yes, On "Silent Mode"
      91
    • No (I use an Admin Account)
      496
    • No (I use a Standard Account)
      39
    • I don't use Windows Vista
      118
  2. 2. Have You Ever Been Saved By UAC?

    • Yes
      226
    • No
      932
    • I don't use Windows Vista
      106


Recommended Posts

  • 1 month later...

UAC is the first thing i disable on every Vista system i setup... UAC is a royal pain in the *SS, and most of my clients absolutely hate UAC, because it constantly nags/annoys the user about the most trivial activities. UAC just gets in the way of getting real work done.

UAC is not a feature, it's a bug, and if microsoft was serious about securing the OS, then they would never have hacked together a crappy/half-assed/stop-gap measure like UAC.

UAC is the first thing i disable on every Vista system i setup... UAC is a royal pain in the *SS, and most of my clients absolutely hate UAC, because it constantly nags/annoys the user about the most trivial activities. UAC just gets in the way of getting real work done.

UAC is not a feature, it's a bug, and if microsoft was serious about securing the OS, then they would never have hacked together a crappy/half-assed/stop-gap measure like UAC.

Wow, I seriously pity any client you have, if that's the best you can come up with. Do us a favor and get out of the field before you do any more damage.

Ok, I'm not claiming to be an expert.

But let us say i follow the turn UAC off camp,

What's the worst that could happen considering the arguments for and against, i end up giving malware admin access that wasn't intended as mentioned above.

Now considering I don't turn it off,

I'm annoyed daily when I'm renaming files editing ini files in program files(which i now know i can find in the virtual store thanks topic :D).

considering the two worst scenario outcomes I can tell you I personally would rather be "Protected" and annoyed.

Edit: Wow 26 pages, I think this thread has gotten way too big, and i only read until page 9, and even rorm the first 3 pages just saw people repeating themselves, reckon the facts from this topic just need to be pinned, and then locked,

but its not my place to back seat mod....

Edited by ryan_the_leach

UAC in Vista was horrible, but since I moved to Windows 7, i have it turned on default settings - I only see it when a program needs to elevate itself, which hardly ever happens - and it saved my ass a couple of times too, the icon overlay usually gives you a heads up, when an app is not supposed to make use of the administrator privileges. A great thing!

  • 1 month later...

I like UAC. I run as a standard user and my Admin account has a password. Despite all of that you never know when something might get through, so UAC is turned on, just in case. It is slightly annoying but not nearly as annoying as many make it out to be.

As I stated in another thread I need an AV because all the systems at one of my client's office are infected and I have to connect my USB drive there to exchange data, I also bring back viruses/malware from there and for me the combination of Norton AV 2009 and UAC is golden.. no infections so far since I started using these 2.. UAC doesn't let the exe files run without consent and NAV cleans them off. I feel almost nothing can sneak through and infect me system (Y)

Sigh... when will that crap die.

It's a non-issue. UAC in Win7 works as intended and should be left at the default setting for most users (the UAC settings dialog explains which option you should use based on your usage habits).

Is it better to run as a standard user and elevate as necessary? I'll be reinstalling 7 when the final comes out so I'll switch to doing that if there is a genuine benefit over running as admin at max UAC settings.

The most secure thing you can do is to run as a standard user, and use Fast User Switching to switch to an administrator account for admin tasks.

A step down from that is to use OTS (Over The Shoulder) elevation, where you run as a standard user but run admin tools as an Administrator on the same desktop. To make this safer you'll want to turn on the option that requires a Ctrl+Alt+Del press before elevating, since you'll have to type a password, and you want to make sure the dialog isn't being spoofed. However, this is not a security boundary because non-admin and admin apps are sharing the same desktop.

A step down from that is UAC at the maximum setting. This is much easier to live with because you don't need to enter a password (and don't need the C+A+D press to protect from spoofing) and the apps still run with your user profile and such. Again this is not considered a security boundary because non-admin and admin apps share the same desktop.

-- The above two options are safest at times when there are no admin apps are running --

A small step down from that is the default Win7 configuration where you aren't prompted for changes to Windows settings. This reduces the barrier between non-admin and admin applications, but maintains the same barrier between protected applications (like the IE Protected Mode and Chrome sandboxes) and normal applications.

There's another notch below that where the secure desktop switch is not enabled, opening up the possibility that someone could tamper with the consent dialog.

Below that is disabling UAC entirely. This is a very bad idea because it removes the "low integrity" option used for things like IE's Protected Mode and Chrome's sandbox. That is a very important and useful security feature for mitigating the impact of exploits against the most common attack surfaces.

Across these options you have trade-offs between safety and useability. The default option is meant to provide the best balance for most users.

A step down from that is UAC at the maximum setting. This is much easier to live with because you don't need to enter a password (and don't need the C+A+D press to protect from spoofing) and the apps still run with your user profile and such.

that's right and this way it was done in Vista.

Again this is not considered a security boundary because non-admin and admin apps share the same desktop.

Yes it it. The IL levels prevent you from attacking an admin app from a non-admin app.

Across these options you have trade-offs between safety and useability. The default option is meant to provide the best balance for most users.

no, it only opens a security whole which can be used very easy run apps with admin rights without accepting the UAC prompt. If Average Joe got a mail with a link to get a free cool game and the chance to win a few bucks he will download the tool and try to run it. Under Vista UAC prompt was shown and this unsettles him and de doesn't accept it. With Win7 the apps can use the Explorer, DWM or several other MS apps to bypass the UAC prompt and still get admin rights.

And this is WRONG!

The IL levels prevent you from attacking an admin app from a non-admin app.

No, this is not the purpose of IL levels (in every Windows NT version any admin app can't be attacked by a non-admin app). The purpose of IL levels is preventing an app1 to attack another app2 which runs with the same privileges of app1 i.e. app1 and app2 are running with the same privileges but different integrity levels.

Edited by jamesVault
  • 2 months later...
I'm hoping future versions will not have an option to disable UAC, any insider info on that possibility?

That should NOT happen. People should have the ability to customize they're computer, I personally don't like **** popping up whenever I click to run programs, it happens everytime firefox starts up, some java **** or something.

That should NOT happen. People should have the ability to customize they're computer, I personally don't like **** popping up whenever I click to run programs, it happens everytime firefox starts up, some java **** or something.

It should have happened in Windows 7. Microsoft should have hard coded UAC at default with NO way to change it period. I have never ever had a UAC prompt for Firefox ever if you are getting them you have something on your end.

  • 6 months later...
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Microsoft is bringing big performance improvements to OneDrive on Mac by Taras Buria Microsoft has announced a major update for the OneDrive client on macOS. Today, the company released version 26.098, promising significantly faster sync, optimized CPU usage, a smaller memory footprint, and better energy efficiency. In a newly published blog post, Microsoft acknowledged that changes implemented in OneDrive for Mac in 2022 brought some unwanted side effects. Due to architectural changes and the need to keep the OneDrive sync engine unchanged, Microsoft created a hidden cache folder. With time, it would cause reliability and performance issues for customers. Now, Microsoft is ditching the old engine for native sync, delivering a faster, more reliable experience. As a result of this change, OneDrive for Mac now integrates more deeply into the operating system, offers about two times faster sync performance, and uses fewer system resources. While the hidden folder still exists, the app only uses it to store files that have not been uploaded yet, link file types, and macOS-related packages. In total, even when holding hundreds of files, the temporary folder does not take more than a couple of megabytes on the drive. Besides optimizations, the new sync engine enables external drive support, allowing you to keep your OneDrive folder on a removable drive (it should meet all the requirements). Microsoft is now rolling out the updated OneDrive client for Microsoft 365 Insiders. To check if your Mac has the new sync engine, go to the About tab and check the app version. If it ends with something like 26H, you are on the new engine. If not, you are on the old one. Microsoft says it will take a few weeks to complete the rollout to Insiders, but it won't say when to expect the update in the stable channel. Big performance updates for OneDrive on Mac came right after Microsoft confirmed it would soon kill document editing in Office 2019 for Mac due to expiring certificates. This change will force users to look for alternatives or switch to Microsoft 365.
    • Sorry but that makes no sense. What does using the same laptop have to do with anything? 
    • Playground drops 30 minutes of Fable gameplay, shows off life sim and morality system by Pulasthi Ariyasinghe Playground Games gave fantasy RPG fans a new look at its Fable reboot last Sunday at the Xbox Games Showcase. While that was a short cinematic trailer revealing the main villain of the storyline, played by Hayley Atwell, today, the development team released an entire gameplay demo to show off the game in action. There is some combat and action near the end of it, but most of the demo is focused on the game's NPC simulation, relationships, choices players can make, and the complex reputation system. The studio is touting over 1,000 hand-crafted NPCs who have jobs, homes, routines they follow in their villages and outskirts, and a memory of what is going on in the world and what actions the player has done. All of these are voiced by real people too. The demo begins with a short interaction with a butcher who wants to kill a talking pig named Colin. The protagonist chooses to save Colin by paying the butcher a bunch of gold for his troubles, giving the hero a rise in reputation for being shrewd, merciful, and virtuous. There were also options to simply let Colin get killed or even fight the butcher for the pig instead of paying him. How NPCs judge the player depends on how they interact with the world. https://www.youtube.com/watch?v=doV0yq4kAP0 Later, the demo shows off how purchasing and managing businesses work, where players can hire employees, change their wages, tweak the price of the shop items, and reap profits if they do well. Different NPCs react differently to each type of reputation the player is touting. One shop owner jacks up prices by 80% just because the player is rich and owns businesses. The demo even shows the player deciding to attack random villagers and causing a ruckus in the streets, turning the hero into a criminal. This is where the magic combat systems are shown off, where the player can teleport, turn enemies into chickens, sword-fight, and more. "This is how you’ll build an extraordinary life in Fable. It’s all about shades of grey – it’s not us or the game telling you what is good and what is bad," says Dan Greer, Lead Game Designer. "With the Living Population, it’s the NPCs themselves judging your actions." Fable is releasing across PC and Xbox Series X|S on February 23, 2027. Premium Edition owners will be able to play starting on February 18 instead. Xbox Game Pass subscribers will also be able to jump in at launch for no extra cost.
    • Still 93% off: Microsoft Visual Studio Professional 2026 lifetime digital license by Steven Parker Today's highlighted deal comes via our Apps + Software section of the Neowin Deals store, where for a limited time you can still save 93% on Microsoft Visual Studio Professional 2026. Code Faster, Work Smarter with Visual Studio 2026 Visual Studio Professional 2026 is a fully featured development environment that developers around the world know & love — now enhanced with deeper AI integration, improved performance & more powerful collaboration tools. Built as a 64-bit IDE, it makes it easier than ever to work with very large solutions & complex workloads. Boost your productivity, write high-quality code & re-imagine team collaboration with an advanced suite of tools & built-in integrations designed to tackle the most demanding development workflows & deliver modern, cloud-connected applications. Build across languages and platforms Craft cross-platform mobile & desktop apps with .NET MAUI Build responsive Web UIs in C# with Blazor Build, debug, & test .NET & C++ apps targeting Windows, Linux & containers Use hot reload capabilities across .NET & C++ apps to apply code changes instantly Edit running ASP.NET/ASP.NET Core pages in the web designer view Integrate seamlessly with Azure, GitHub & other DevOps workflows Type less, code more with Intellicode and AI Understand your code context: variable names, functions, libraries & the type of code you’re writing Complete a line or block of code based on patterns learned from your codebase Get a ranked list of next best suggestions, helping you code more rapidly & accurately Use built-in AI-assisted refactoring & code suggestions to reduce bugs & boilerplate Gain deep insights into your code with codelens Reveal crucial information such as recent changes, authors, tests & commit history directly in the editor See test status & references without leaving your code Make informed decisions with a comprehensive overview of your codebase and activity Collaborate seamlessly with live share Run real-time collaboration sessions with teammates — no need for them to clone repos or install all dependencies Speed up your team’s edit & debugging cycles with personalized sessions, access controls & custom editor settings Keep everyone aligned so your team’s code stays consistent & maintainable Good to know Length of access: Lifetime License type: Professional, single-user license Redemption deadline: Redeem your code within 30 days of purchase Access options: Desktop installation on supported Windows operating systems Max number of device(s): 1 Version: Visual Studio Professional 2026 Languages supported: English, Chinese (Simplified), Chinese (Traditional), Czech, French, German, Italian, Japanese, Korean, Polish, Portuguese (Brazil), Russian, Spanish, and Turkish. Updates included: Minor updates and security fixes for the 2026 Professional release channel (according to Microsoft’s lifecycle policy) Activation method: Online activation with Microsoft account required Microsoft Visual Studio Professional 2026 normally costs $499.99, but this deal can be yours for just $34.97, that's a saving of $465. For full terms, specifications, and license info please click the link below. Get Visual Studio 2026 now for just $34.97 (was $499.99) Time limited deal Although priced in U.S. dollars, this deal is available for digital purchase worldwide. Support queries If you have queries or need support for any of the Neowin Deals, please use the contact form here. Neowin Deals are managed and sold by StackCommerce who represent Neowin on an affiliate basis. Why we post these deals We post these because we earn commission on each sale so as not to rely solely on advertising, which many of our readers block. It all helps toward paying staff reporters, servers and hosting costs. So for those that keep moaning and complaining, be thankful we're still online for you to even do that. Other ways to support Neowin Whitelist Neowin by not blocking our ads Create a free member account to see fewer ads Make a donation to support our day to day running costs Subscribe to Neowin - for $14 a year, or $28 a year for an ad-free experience Disclosure: Neowin benefits from revenue of each sale made through our branded deals site powered by StackCommerce.
    • My current phone, on left, is starting to go to sleep, and not turning on, even though I press the power button 100 times. Like CPR.   I tried factory resetting it, and nothing changed. So it's the hardware failing. I currently am using Twigby as my service provider. Cheapest I can get around here. But all their phones are carp.. https://www.twigby.com/shop/twigby-phones A friend warned me about the Moto G, as his neice has one, and isn't that good at $130. Also the Samsung A15 is laughable at best. Everything else is expensive af. I want android, (hate iOS) any version, that works with Twigby, under $100, please. Refurbished/Used is OK with me, as long as it isn't beat up.   If you know the IMEI number, you can see if it works with Twigby: https://www.twigby.com/page/byod
  • Recent Achievements

    • Week One Done
      StaticMatrix earned a badge
      Week One Done
    • Rookie
      lamborghiniv10 went up a rank
      Rookie
    • One Month Later
      pinnclepd earned a badge
      One Month Later
    • First Post
      X-No-file earned a badge
      First Post
    • One Month Later
      johnjacobb40 earned a badge
      One Month Later
  • Popular Contributors

    1. 1
      +primortal
      516
    2. 2
      PsYcHoKiLLa
      210
    3. 3
      +Edouard
      147
    4. 4
      Steven P.
      92
    5. 5
      ATLien_0
      82
  • Tell a friend

    Love Neowin? Tell a friend!