Check: WN11-SO-000270
Microsoft Windows 11 STIG:
WN11-SO-000270
(in versions v1 r6 through v1 r1)
Title
User Account Control must run all administrators in Admin Approval Mode, enabling UAC. (Cat II impact)
Discussion
User Account Control (UAC) is a security mechanism for limiting the elevation of privileges, including administrative accounts, unless authorized. This setting enables UAC.
Check Content
If the following registry value does not exist or is not configured as specified, this is a finding: Registry Hive: HKEY_LOCAL_MACHINE Registry Path: \SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\ Value Name: EnableLUA Value Type: REG_DWORD Value: 1
Fix Text
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> Security Options >> "User Account Control: Run all administrators in Admin Approval Mode" to "Enabled".
Additional Identifiers
Rule ID: SV-253474r954043_rule
Vulnerability ID: V-253474
Group Title: SRG-OS-000373-GPOS-00157
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-002008 |
The organization, for PKI-based authentication, employs a deliberate organization-wide methodology for managing the content of PKI trust stores installed across all platforms including networks, operating systems, browsers, and applications. |
CCI-002038 |
The organization requires users to reauthenticate upon organization-defined circumstances or situations requiring reauthentication. |