Accounts: User Account Control approval mode for the built-in Administrator must be enabled

b505fc16-70d3-4275-bcc5-02fac2fdb3af

User Account Control (UAC) is a security mechanism for limiting the elevation of privileges, including administrative accounts, unless authorized. This setting configures the built-in Administrator account so that it runs in Admin Approval Mode. Satisfies:

Remediation

To fix this configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> Security Options >> "User Account Control: Admin Approval Mode for the Built-in Administrator account" to "Enabled".

STIG: Server 2019: https://www.stigviewer.com/stig/windows_server_2019/2020-06-15/finding/V-93431
Server 2016: https://www.stigviewer.com/stig/microsoft_windows_server_2016/2022-03-01/finding/V-225061
Desktop: https://www.stigviewer.com/stig/microsoft_windows_10/2022-04-08/finding/V-220944

STIG: SRG-OS-000373-GPOS-00157, SRG-OS-000373-GPOS-00156
NIST 800-53: CM-6(a),IA-11
PCI v3.2: 8.1.8
PCI v4: 8.2.8
SIG: H.7.10, H.7.10.1, H.20.1