The Great UAC Debate!


UAC  

1412 members have voted

  1. 1. Do You Use UAC?

    • Yes
      477
    • Yes, On "Silent Mode"
      91
    • No (I use an Admin Account)
      496
    • No (I use a Standard Account)
      39
    • I don't use Windows Vista
      118
  2. 2. Have You Ever Been Saved By UAC?

    • Yes
      226
    • No
      932
    • I don't use Windows Vista
      106


Recommended Posts

UAC is the first thing i disable on every Vista system i setup... UAC is a royal pain in the *SS, and most of my clients absolutely hate UAC, because it constantly nags/annoys the user about the most trivial activities. UAC just gets in the way of getting real work done.

UAC is not a feature, it's a bug, and if microsoft was serious about securing the OS, then they would never have hacked together a crappy/half-assed/stop-gap measure like UAC.

You must be just like the computer repair place in the next town. She's always turning UAC off when ever a computer comes into her shop. I swear she considers it "Tweaking" the machine. But that's ok, I always turn it back on whenever I work on a computer she has previously touched.

Can't believe this thread is still going. Anyway, as was discussed MUCH earlier in this thread, instead of disabling UAC just set it to quiet mode. You still retain most of its functionality without the annoying prompts.

I was reading up on quiet mode

Is the "quiet" mode of UAC less secure?

If you've used TweakUAC, you've seen the "quiet" option it offers that lets you suppress the elevation prompts of UAC without turning the UAC off completely. In such a mode, you keep all the positive effects of UAC, such as Internet Explorer operating in the protected mode, applications starting without the administrative privileges by default, etc. The only thing that gets changed is that you will no longer see the infamous "Windows needs your permission to continue" messages whenever you attempt to make a change to your Vista configuration, or when you run a program that needs administrative rights.

So in quite mode if you run an app that needs admin privileges, it just gives it to the application? How the hell is that secure? Sure it doesn't nag you, but if an application on my computer wants admin privileges I want windows to prompt me.

So in quite mode if you run an app that needs admin privileges, it just gives it to the application? How the hell is that secure? Sure it doesn't nag you, but if an application on my computer wants admin privileges I want windows to prompt me.

It will still prompt you for third-party software, it's just certain signed Microsoft executables that are allowed to elevate without prompting.

This does somewhat reduce security (if something else can ride along with the automatic elevation), but it's always about compromises. It's better than having someone disable it completely.

(Also, you can actually disable prompts while still keeping things like Protected Mode IE. Forgive me if that's what this "TweakUAC" actually means.)

  • 2 months later...
  • 3 weeks later...

Did you notice that UAC takes longer to show up if executable is very large in size?

E.g. when launching a setup that is 150MB large, there is noticeable delay in the time UAC prompt shows up, never mind speaking of larger .exe files;

it's like it's "reading" the whole executable before launching the Yes/No dialog.

Hello.

I had viruses on my computer. But I think UAC kinda saved my ass and made the damage a lot less. First I had one of the viruses that wanted access to something, I pressed no. That didn't come up again. Then this more tricky one came, it kept spamming me with new UAC and wanted access to cmd to do stuff. It kept coming and coming and I keep hitting no.

I don't know if that saved me, but it probably did. Does anyone know if UAC stops giving prompts if you say no for a number of times or did it somehow run? Because while that was happening I did CTRL - ALT - DEL fast to stop all process.

Yeah well so... I don't know 100 % if UAC helped me here. But it seems like it, because some things the viruses were supposed to do (according to tech. info) didn't happen, so it was probably UAC.

Hello.

I had viruses on my computer. But I think UAC kinda saved my ass and made the damage a lot less. First I had one of the viruses that wanted access to something, I pressed no. That didn't come up again. Then this more tricky one came, it kept spamming me with new UAC and wanted access to cmd to do stuff. It kept coming and coming and I keep hitting no.

I don't know if that saved me, but it probably did. Does anyone know if UAC stops giving prompts if you say no for a number of times or did it somehow run? Because while that was happening I did CTRL - ALT - DEL fast to stop all process.

Yeah well so... I don't know 100 % if UAC helped me here. But it seems like it, because some things the viruses were supposed to do (according to tech. info) didn't happen, so it was probably UAC.

UAC stopped the nasty stuff from making changes to your system, that's why you didn't experience all the symptoms. Technically malware can nag you with UAC prompts until you out of desperation click 'Yes' but terminating the process and running a scan immediately is the best thing to do. (Y)

UAC stopped the nasty stuff from making changes to your system, that's why you didn't experience all the symptoms. Technically malware can nag you with UAC prompts until you out of desperation click 'Yes' but terminating the process and running a scan immediately is the best thing to do. (Y)

Yeah. It actually does seem like that. For example the viruses were supposed to break my internet, but I could access it normally. Some registry changes that should of been done weren't, but only some. It just limited things, which was not all that bad. I didn't check it much though, I formatted the next day just to be on the safe side (you never know what you get into your PC).

Something should of been done against that nagging though; it was really hard and I seriously didn't know what to do. I did no, no, no, no, no then suddenly it stopped? or maybe it ran? or maybe my CTRL ALT DEL accidently pressed yes? No idea.

But for sure I will keep UAC turned on on every computer I ever fix and help people with it, because I saw my myself that it helped... even if it would not limit damages atleast it gave me a sign that I have an infection.

So people, Turn your UAC on! It's not just for your own sake, it's for the your fellow computer users too.

Day by day viruses are getting more. They are also getting more dangerous and finding easier ways to infect us. People who say common sense have no idea what they are doing; I was one of the "common sense people". I was one of those "Don't format, just remove the virus." But then you understand just by going to your daily website, you can infect your PC with a malware cocktail you will learn common sense is useless here.

I noticed a very interesting thing when I had UAC off, you couldn't elevate processes. With UAC on if you say "Run as Administrator" it will actually do as you say and run as if there is nothing in your way, as long as you allow it via the pop up. However, with UAC off and selecting "Run as Administrator", you really don't get that much of a change and end up having the process be not as elevated.

I noticed a very interesting thing when I had UAC off, you couldn't elevate processes. With UAC on if you say "Run as Administrator" it will actually do as you say and run as if there is nothing in your way, as long as you allow it via the pop up. However, with UAC off and selecting "Run as Administrator", you really don't get that much of a change and end up having the process be not as elevated.

I think you misunderstand. There's no "not as elevated." What normally happens when you have administrator approval mode (AAM, what you mean by UAC) enabled is that your account has two security tokens. One with the rights of an administrator, and one with the rights of a standard user.

By default everything runs with the standard token, unless you click yes to the elevation prompt. When you do that, it switches tokens and runs that specific process with the administrator rights. If you disable AAM, then this standard user token goes away and everything always runs with the administrator token.

In other words, if you disable AAM, then your account becomes a full administrator account and every single thing you click always runs with full administrator rights and full access to your system.

I think you misunderstand. There's no "not as elevated." What normally happens when you have administrator approval mode (AAM, what you mean by UAC) enabled is that your account has two security tokens. One with the rights of an administrator, and one with the rights of a standard user.

By default everything runs with the standard token, unless you click yes to the elevation prompt. When you do that, it switches tokens and runs that specific process with the administrator rights. If you disable AAM, then this standard user token goes away and everything always runs with the administrator token.

In other words, if you disable AAM, then your account becomes a full administrator account and every single thing you click always runs with full administrator rights and full access to your system.

So, can you say that there is no need to have a "Standard account" for web browsing and these stuff if you have Vista or 7?

Or is it still safe to have one?

And seriously - anyone knows if UAC stops prompting you if you have a malware that keeps wanting access? It gets so annoying and one almost gets depressed haha.

So, can you say that there is no need to have a "Standard account" for web browsing and these stuff if you have Vista or 7?

Or is it still safe to have one?

The best setup is to run as a standard user, if you can live with the hassle of having to log onto an administrator account to make system changes (the credentials prompt is not secure.) If you can't, then admin approval mode is a good compromise.

And seriously - anyone knows if UAC stops prompting you if you have a malware that keeps wanting access? It gets so annoying and one almost gets depressed haha.

Not sure what you mean. Are you saying that your system is infected by something that keeps asking for administrator rights? What you have to understand about UAC (AAM) is that it's not a defense against malware.

First of all, malware doesn't technically need administrator rights to do bad things. Most are designed that way today, but it's not something technically needed. Malware running as standard user still has access to all your data and still has access to the internet. It could still steal all your personal files and make you part of a botnet. Getting administrator rights is merely a convenience that lets it hide itself better.

Second, malware running as standard user can trick you into elevating it, for example by replacing a file that you've downloaded with malware before you have a chance to run it, or by taking advantage of the way the library loader works in order to piggyback on a legitimate elevation request by a program you trust. It's very hard to know what you're actually saying yes to when you see a UAC prompt. For this reason, it's not considered a security boundary at all. It merely exists as a convenience.

It is not safe to run any executables you don't trust, period. Just don't do it. The second you double-click any executable, your system could be compromised.

The best setup is to run as a standard user, if you can live with the hassle of having to log onto an administrator account to make system changes (the credentials prompt is not secure.) If you can't, then admin approval mode is a good compromise.

Not sure what you mean. Are you saying that your system is infected by something that keeps asking for administrator rights? What you have to understand about UAC (AAM) is that it's not a defense against malware.

First of all, malware doesn't technically need administrator rights to do bad things. Most are designed that way today, but it's not something technically needed. Malware running as standard user still has access to all your data and still has access to the internet. It could still steal all your personal files and make you part of a botnet. Getting administrator rights is merely a convenience that lets it hide itself better.

Second, malware running as standard user can trick you into elevating it, for example by replacing a file that you've downloaded with malware before you have a chance to run it, or by taking advantage of the way the library loader works in order to piggyback on a legitimate elevation request by a program you trust. It's very hard to know what you're actually saying yes to when you see a UAC prompt. For this reason, it's not considered a security boundary at all. It merely exists as a convenience.

It is not safe to run any executables you don't trust, period. Just don't do it. The second you double-click any executable, your system could be compromised.

Sad but true. And especially the last one, it's hard to trust anything. How do you know the Firefox you are downloading is safe and clean? A few weeks ago some famous IRC Server (UnrealD? or something similiar) was revelead having a backdoor for 9 months without the developers even noticing. And a lot of people would say that is a trusted file.

You can't trust anything on the internet. I didn't believe this before but now when I see what can really happen, you don't really have a chance and your best shoot is to: 1) Have backups. 2) Protect yourself with 50 layers of security tools (haha). 3) Be very, very, very, very careful when downloading files & browsing.

  • 3 weeks later...

I have UAC on and left at default settings. The only time I notice it is when I go to install something, which is very rare. I've read things about UAC before and people act as if it's a constant annoyance, forcing them to disable it. Why is this? What are you doing on a daily basis that is making the UAC prompt you several times? o_O

I have UAC on and left at default settings. The only time I notice it is when I go to install something, which is very rare. I've read things about UAC before and people act as if it's a constant annoyance, forcing them to disable it. Why is this? What are you doing on a daily basis that is making the UAC prompt you several times? o_O

7-Zip couldn't extract newer minefield builds on top of older ones, it always failed.

I just then set it to run with Admin privileges all the time, but that would make UAC prompt me all the time. So I disabled UAC prompting.

That was satisfactory for some time.

Then, I noticed some things starting up extremely slowly (Gothic II auto-run or installer was one of them I think). So, I simply disabled the UAC driver. Surprisingly only a few people realize that this is the only true way to disable UAC.

Whatcha know? Windows 7 felt snappier. And well no annoyingly long pause before launching some programs.

So,

Annoyances can be avoided by turning off UAC prompts as well as making program always run with admin privileges. Ex: 7-Zip

Disabling UAC prompts != disabling UAC; disabling UAC is done by nuking the driver.

Nuking UAC = startup performance increase in some applications.

  • 3 months later...
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Microsoft releases major feature updates for stock Windows 11 apps by Taras Buria In addition to releasing new Windows 11 preview builds, Microsoft announced that inbox Windows apps now have dedicated release notes in the official documentation. At long last, users have access to all the release notes for each app, with changes listed in chronological order. Microsoft used to announce feature updates for stock apps with each build. Now, with Windows Insider release notes hosted on the Microsoft Learn website, each app has a dedicated space for its changelog, which is very useful for those who want to track new features and improvements. Alongside that, Microsoft dropped massive feature updates for six stock apps: Clock, Media Player, Calculator, Voice Recorder, Photos, and Paint. Each app packs quite a lot of changes and new capabilities, so here are the release notes. Here are quick notes so that you can jump to the app you are interested in the most: Calculator Camera Clock Media Player Paint Photos Sound Recorder Here is what is new for the Calculator in version 11.2605.9.0: More accurate square-root results — Fixed rare cases where a calculation that should equal zero (like sqrt(2.25) - 1.5) returned a tiny leftover value instead. Readable text in High Contrast themes — Settings text now shows the correct colors in the High Contrast Aquatic and Desert themes. Fixed layout for right-to-left languages — For languages like Arabic and Hebrew, the graph, number pad, equation fields, and scroll buttons now appear correctly oriented. Reliable launch after upgrading — Fixed an issue where upgrading from much older versions could leave outdated settings that stopped the app from opening. Here is what is new for the Camera app (version 2026.2605.7.0): Zoom slider works on more cameras — The zoom slider now works on the latest cameras, respects your system zoom settings, and updates instantly when you change those settings. Full range of zoom levels — Fixed an issue where the zoom slider only showed three steps on some devices that zoom in finer increments. Front camera works on more devices — Resolved a problem that blocked the front-facing camera on certain wide-angle devices. More video resolution choices — You can now pick video resolutions that were previously hidden; the app shows a heads-up warning instead of removing them. QR links you can still use — When a scanned QR code points to something with no matching app, the link is now copied to your clipboard (with a notification) while still offering a Store search. Smarter default settings — When you haven't set a preference, the app now follows your system settings by default. The Clock app has a massive changelog with the following improvements in version 11.2605.9.0: Timers keep counting after they hit zero — When a timer runs out, it now keeps counting up (for example, -00:27:31) so you can see how far past the time you've gone. You can turn off the daily goal — Focus Sessions now include an "Off" option so you can skip setting a daily goal entirely. New 15-minute snooze option — Alarms now offer a 15-minute snooze interval. Run up to 3 countdowns at once — The Countdown Widget now supports three simultaneous countdowns, up from two. Timer Widget notifications now appear — Fixed an issue where the "timer finished" notification didn't show when the timer was started from the widget. Less clutter in Focus Sessions — Tasks you've already completed no longer show up in the Focus Session task list. More accurate focus progress — Fixed a rounding issue that could show your daily focus progress as a minute short (for example, 49 minutes instead of 50). Smoother World Clock comparisons — The World Clock compare page now loads dates as you scroll, so it feels more responsive. Up-to-date World Clock locations — Refreshed country and city names to match their current names. Correct sun and moon icons during midnight sun — Fixed an icon that wrongly showed a moon during all-day daylight in polar regions. Fixed back-button behavior in clock comparisons — Pressing back once now takes you back as expected, instead of jumping the date to 1926. Corrected the Newfoundland time zone — Newfoundland now uses the right time zone (St. John's). Disabled alarms stay looking disabled — Editing a turned-off alarm no longer makes it appear turned on. Cleaner timer cards — The expand button is now turned off on timer cards that have no time set, preventing actions that wouldn't do anything. Clearer theme setting — Updated the wording to "Choose your preferred app theme." Smoother Settings links — The "About" links in Settings no longer trigger an unexpected "switch apps" prompt. Fixed spacing in Spotify settings — Corrected uneven spacing in the Spotify settings card. Better focus visibility in High Contrast — The focus highlight in World Clock is now clearly visible in the High Contrast Aquatic and Desert themes. No more double announcements — Screen readers no longer read the timer value twice. Countdown names read correctly — Screen readers now properly announce the name of each countdown. Keyboard focus stays put — Focus no longer disappears after you press the Timer Reset button. Clearer alarm toggle for screen readers — Tidied up how the alarm on/off switch is announced. The Media Player app received plenty of changes as well (version 11.2605.14.0): Custom captions — You can now personalize how closed captions appear, with caption styling tied to your Windows caption settings, plus a quick link to open those settings directly. "Indexing" banner in the play queue — When your media library is still being scanned, a banner now explains why some items may not appear yet. Fixed the look of selected items — Corrected a layout glitch with selected items in lists. Fewer playback failures — Improved how the app recognizes supported file types, so more files play without issues. Playlists need a name — You can no longer accidentally save a playlist with a blank name. Cleaner look for empty playlists — Improved how a playlist appears when it has no items yet. More stable play queue edits — Fixed a crash that could happen when changing the play queue while the app was switching between sessions. Clearer "missing codec" message — Improved the dialog that appears when a file needs a codec you don't have, with clearer guidance on what to do. A big update is also available for Paint in version 11.2605.61.0: Adjustable eraser transparency — You can now control how transparent the eraser is. Cleaner stamp brush strokes — Fixed visible color shifts and artifacts when using stamp-style brushes. JPEG photos save in place — Opening a rotated JPEG and pressing Save now overwrites the original instead of unexpectedly prompting "Save As." No more crash on bad image files — Opening a damaged or invalid image, from within the app, by double click, or commandline, now shows a clear error message instead of closing the app. Classic selection behavior restored — The selection outline now hides while you move, resize, or rotate a selection, just like in classic Paint. Tidier AI image panel — Fixed missing spacing at the bottom of the AI image generation panel for a cleaner layout. Visible button hover in light theme — Toolbar split buttons now show a clear hover highlight in the light theme. Snappier toolbar — Streamlined how the ribbon lays out, giving a small speed boost at startup. Fewer background crashes — Fixed a crash that could happen while background tasks were finishing up. Stable app shutdown — Prevented rare crashes when closing the app. Fixed layer removal glitch — Deleting the active layer no longer leaves the layers list in an inconsistent state. Here is what is new in the Photos app (version 2026.11060.2004.0): AI watermarking — AI-generated or edited images can now carry a visible Copilot watermark. You choose Never, Always, or Ask Every Time in Settings, with a confirmation when saving. The watermarking is off by default in settings. Better viewing of small images and pixel art — Tiny images (like 16×16 pixel art) now zoom in far more to fill the screen and stay crisp instead of looking blurry. Select scanned text with the keyboard — When text is detected in an image, you can now navigate and select it using the arrow keys, Shift+Arrow, Home/End, and Ctrl+A, with a clear focus highlight. Fixed a crash in text recognition — Resolved a crash that could close Photos while detecting text in images; the app now recovers gracefully. Easier keyboard navigation — Tabbing through the navigation bar no longer stops on hidden controls, so it takes a single Tab to move past it instead of three. And finally, here is the Sound Recorder (version 11.2605.1.0): Waveform shows with Bluetooth mics — The live waveform now displays correctly when you record using a Bluetooth audio device. No more stray scrollbar — A non-working horizontal scrollbar no longer appears at the bottom of the waveform unless you've zoomed in. Mark button ready right away — The Mark button no longer looks grayed out until you hover over it after opening the app. Markers hidden for WAV files — Markers are now turned off for WAV recordings, since that format can't store them — so they're no longer lost silently. Smoother deleting — Quickly pressing Delete and Enter to remove several recordings in a row no longer triggers a "file doesn't exist" error. Fixed a memory issue — Resolved a memory leak that occurred each time a recording started. You can find all these changelogs in the official documentation here.
    • again, an article about Microsoft Edge and ridicules hater's comments
    • From this very same article: "For organizations that prefer a “more deliberate pace”, the Extended Stable channel remains an option."
    • Or every other browser, because they all behave the same, at least the mainstream ones. Firefox does exactly the same: background updates, restart to install them. Haters gotta hate, I guess.
  • Recent Achievements

    • Very Popular
      AndrewSteel earned a badge
      Very Popular
    • Veteran
      Taliseian went up a rank
      Veteran
    • One Month Later
      Clizby earned a badge
      One Month Later
    • One Month Later
      Timaximus earned a badge
      One Month Later
    • Week One Done
      Timaximus earned a badge
      Week One Done
  • Popular Contributors

    1. 1
      +primortal
      495
    2. 2
      PsYcHoKiLLa
      166
    3. 3
      +Edouard
      162
    4. 4
      Steven P.
      86
    5. 5
      ATLien_0
      77
  • Tell a friend

    Love Neowin? Tell a friend!