An administrator needs to configure a local Windows security policy so that standard users cannot install unauthorized software, even if they have local administrator rights on non-domain joined workstations. Which User Account Control (UAC) policy setting enforces administrator approval for all applications requiring elevation?
Trap 1: User Account Control: Detect application installations and prompt…
This specific policy controls heuristics for identifying installation files but does not force general administrative applications to require explicit user approval for elevation across all operational scenarios. It focuses strictly on heuristic detection rather than universal elevation enforcement.
Trap 2: User Account Control: Behavior of the elevation prompt for…
This setting merely dictates how the prompt is presented to users already running in Admin Approval Mode, such as prompting for credentials or consent, rather than enabling the enforcement mechanism itself. It assumes the approval mode is already active.
Trap 3: User Account Control: Only elevate executables that are signed and…
This policy restricts elevation strictly to digitally signed binaries, which alters signature validation requirements rather than mandating universal administrator approval for all unsigned or general executable tasks needing elevated privileges.
- A
User Account Control: Detect application installations and prompt for elevation
Why it fails: This specific policy controls heuristics for identifying installation files but does not force general administrative applications to require explicit user approval for elevation across all operational scenarios. It focuses strictly on heuristic detection rather than universal elevation enforcement.
- B
User Account Control: Run all administrators in Admin Approval Mode
This fundamental policy setting governs whether the built-in Administrator Approval Mode is active, splitting user tokens into standard and administrative privileges upon login. Enabling this forces every administrative action to undergo explicit consent verification via a secure desktop prompt.
- C
User Account Control: Behavior of the elevation prompt for administrators in Admin Approval Mode
Why it fails: This setting merely dictates how the prompt is presented to users already running in Admin Approval Mode, such as prompting for credentials or consent, rather than enabling the enforcement mechanism itself. It assumes the approval mode is already active.
- D
User Account Control: Only elevate executables that are signed and validated
Why it fails: This policy restricts elevation strictly to digitally signed binaries, which alters signature validation requirements rather than mandating universal administrator approval for all unsigned or general executable tasks needing elevated privileges.