Accounts: User Account Control approval mode for the built-in Administrator must be enabled


User Account Control (UAC) is a security mechanism for limiting the elevation of privileges, including administrative accounts, unless authorized. This setting configures the built-in Administrator account so that it runs in Admin Approval Mode. Satisfies:


To fix this configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> Security Options >> "User Account Control: Admin Approval Mode for the Built-in Administrator account" to "Enabled".

STIG: Server 2019:
Server 2016:

STIG: SRG-OS-000373-GPOS-00157, SRG-OS-000373-GPOS-00156
NIST 800-53: CM-6(a),IA-11
PCI v3.2: 8.1.8
PCI v4: 8.2.8
SIG: H.7.10, H.7.10.1, H.20.1