Accounts: User Account Control (UAC) must be configured to detect application installations and prompt for elevation

ed5ca948-5cbf-431d-a5da-39d02bd64c48

User Account Control (UAC) is a security mechanism for limiting the elevation of privileges, including administrative accounts, unless authorized. This setting requires Windows to respond to application installation requests by prompting for credentials.

Remediation

To fix this configure the policy value for
Computer Configuration
|_ Windows Settings
|_ Security Settings
|_ Local Policies
|_ Security Options
|_ "User Account Control: Detect application installations and prompt for elevation" to "Enabled".

STIG: Server
2022: https://www.stigviewer.com/stig/microsoft_windows_server_2022/2023-09-11/finding/V-254486
2019: https://www.stigviewer.com/stig/microsoft_windows_server_2019/2023-09-11/finding/V-205718 / https://www.stigviewer.com/stig/windows_server_2019/2020-06-15/finding/V-93525
2016:https://www.stigviewer.com/stig/microsoft_windows_server_2016/2023-08-22/finding/V-225065 / https://www.stigviewer.com/stig/windows_server_2016/2020-06-16/finding/V-73715

Desktop:
W11: https://www.stigviewer.com/stig/microsoft_windows_11/2023-09-29/finding/V-253472
W10: https://www.stigviewer.com/stig/microsoft_windows_10/2023-09-29/finding/V-220948 / https://www.stigviewer.com/stig/windows_10/2021-08-18/finding/V-220948

NIST 800-53B/Rev4 : AC-6
NIST 800-53 rev5: AC-6 SA8(14)
NIST 800-171 Rev2: 3.1.5
NIST 800-171 Rev3 FPD: 3.1.1.d, 3.1.4.b, 3.1.5.a, 3.1.6.a, 3.1.7.a, 3.4.5
NIST 800-171 Rev3: 03.01.01.c.03, 03.01.01.d.01, 03.01.01.d.02, 03.01.04.b , 03.01.05.a, 03.01.05.b, 03.01.06.a, 03.01.07.a, 03.03.08.a, 03.03.08.b, 03.04.05
NIST 800-171A: 3.1.5[a], 3.1.5[b], 3.1.5[c], 3.1.5[d]
NIST 800-171A Rev3: A.03.01.02[02], A.03.01.05.a
PCI-DSS v4.0: 1.3, 7.1, 7.2, 7.2.1, 7.2.2, 7.3, 7.3.1, 7.3.2, 7.3.3
CSCv6: 5.1
CMMC v2 L2: AC.L2-3.1.5
CMMC v2.1 L1: AC.L1-b.1.i
MITRE Att&k: T1087, T1087.001, T1087.002, T1546.011, T1548, T1548.002