Subscribe to Windows IT Pro

 

Get Newsletters

  • Get the Latest News
  • Product Updates
  • Helpful Tricks
  • Productivity Tips

Subscribe Now!

February 08, 2006 12:00 AM

User Account Control in Windows Vista

Windows IT Pro
InstantDoc ID #49347
Rating: (0)

Microsoft recently released the document "Applying the Principle of Least Privilege to User Accounts on Windows XP" (at the URL below), which aims to help you implement least-privileged user accounts (LUAs) in your Windows XP environment. The LUA terminology has been in use for quite a while now. Even so, Microsoft apparently wanted a clearer phrase for the concept. Initially, LUA was renamed User Account Protection (UAP), and most recently, the company landed on User Account Control (UAC), which will be the terminology used from here on out.

http://www.microsoft.com/technet/prodtechnol/winxppro/maintain/luawinxp.mspx

When Windows Vista makes its debut, native UAC will be built into the OS, so you won't have to jump through countless hoops trying to limit use of administrative privileges on your network. Vista will expose new UAC policies that let you better control user accounts.

When using Vista, you'll either be considered a standard user or an administrator with privileges and rights appropriate to those two general types of accounts. For example, there will be 14 different types of administrative consent that cover the usual tasks a person might need to perform.

In general, Vista will operate a bit more like Linux systems when it comes to administrative access. You'll operate on the desktop with least privileges, and your account will have a policy assigned to handle any need for elevation of privileges. Standard users will either be prompted for credentials (username and password) or denied elevated access outright, depending on the policy settings. Administrative accounts will have both those possibilities, plus a Prompt for Consent option. In the latter case, administrators would simply click Yes or No to elevated privileges instead of having to enter their credentials.

Application installation will be an issue for some users, depending on their particular network. Vista will let you control whether elevation takes place when required by an application. Microsoft said that in an enterprise network, such elevation probably won't be required when installation is delegated to Group Policy Software Install (GPSI) or Microsoft Systems Management Server (SMS).

Another policy will govern applications that require elevation of privileges. You'll be able to deny elevation if the applications don't have a valid digital signature. To help with legacy applications that don't adhere to Vista's new architecture, you'll also be able to redirect registry and file writing activity to safe areas on the system. In other words, applications that typically write to the HKEY_LOCAL_MACHINE\SOFTWARE registry subkey or the Program Files, Windows, or Windows\System32 directories will still be able to run, but any write I/O will be written to virtualized locations instead of those actual locations. So the applications will run correctly, but sensitive storage areas won't be overly exposed.

UAC will be a welcome change in Windows that will surely bring greater security. There will of course be the usual learning curve, so the sooner you get started understanding the ins and out, the better off you'll be when you begin to use the OS. You can catch glimpses of developing UAC functionality by reading Microsoft's UACBlog (at the URL below) on the Microsoft Developer Network (MSDN).

http://blogs.msdn.com/uac/default.aspx

Related Content:

ARTICLE TOOLS

Comments
    There are no comments to display. Be the first one!
You must log on before posting a comment.

Are you a new visitor? Register Here

advertisement

advertisement

White Papers

Get your Windows 7 deployment off to the right start by implementing PC lockdown. A locked-down environment is easier and cheaper to support since users are less likely to make unnecessary changes to the core system configuration - read more here!

Essential Guides

Is your iSCSI "lossy"? The reality is that most off-the-shelf Ethernet hardware deployed for iSCSI can lose packets, resulting in slow performance or application downtime. Learn how to assess your current iSCSI infrastructure and engineer an advanced iSCSI SAN infrastructure.

Web Seminars

What's the best way to keep your network safe from malware? In this web seminar, security expert Greg Shields suggests an alternative method to the traditional blacklisting approach that is common with anti-virus and anti-malware solutions.

eLearning Series

We bring the experts direct to you to share their real-world perspective and expertise. During each event, three sessions stream in real time, so you can learn, ask questions, and get solutions.
Upcoming event: Getting the Most with Exchange 2010 with Paul Robichaux

Subscribe to Windows IT Pro!

Windows is a trademark of the Microsoft group of companies. Windows IT Pro is used by Penton Media Inc. under license from owner.