Modifying UAC Settings with Group Policy

by Chris Sanders [Published on 21 Jan. 2010 / Last Updated on 31 May 2009]

User Account Control has its place in some scenarios, but you may find it best to disable it in certain situations. This can be done globally with Group Policy.

User Account Control is one of Windows Vista’s most touted and noticeable features. Designed to alert users when an action is being performed that makes a modification to the system, UAC has its place in several situations. However, you may run into occasions where application compatibility issues require that UAC be disabled.

Rather than painstakingly changing this setting on each individual computer, the change can be made in Group Policy. In order to do this, create a new Group Policy Object and browse to Computer Configuration/Windows Settings/Security Settings/Local Policies/Security Options. On the right hand side of the screen there are a few options we want to configure that will disable UAC.  They are:

  • User Account Control: Behavior of the elevation prompt for administrators - Elevate without prompting
  • User Account Control: Detect application installations and prompt for elevation – Disabled
  • User Account Control: Run all administrators in Admin Approval Mode – Disabled 

You will notice there are quite a few other configurable options for UAC here. When possible, you should try to toy around with these configuration options rather than just disabling UAC when dealing with an application compatibility issue. One last important note, once these settings are applied a computer restart will be required.

Featured Links