Enumerate administrator accounts on elevation

Information

This policy setting controls whether administrator accounts are displayed when a user attempts to elevate a running application. By default administrator accounts are not displayed when the user attempts to elevate a running application.

If you enable this policy setting all local administrator accounts on the PC will be displayed so the user can choose one and enter the correct password.

If you disable this policy setting users will always be required to type a user name and password to elevate.

Solution

Policy Path: Windows Components\Credential User Interface
Policy Setting Name: Enumerate administrator accounts on elevation

See Also

https://techcommunity.microsoft.com/t5/microsoft-security-baselines/windows-11-security-baseline/ba-p/2810772

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-6(10)

Plugin: Windows

Control ID: ad04b0c4a75ca833353953702bb789e51146cc6da6cdacecf7d3f6e135307142