SHARE
Facebook X Pinterest WhatsApp

Learning To Love UAC

User Access Control in Windows Vista has been such a controversial development that it’s worth re-examining periodically. Let’s restate the purpose of UAC: It is to allow the user to run the system as a standard user, not administrator, and still have relatively easy access to privileged operations when they are necessary. UAC (click here […]

Written By
thumbnail Larry Seltzer
Larry Seltzer
Jun 4, 2008
Channel Insider content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

User
Access Control in Windows Vista has been such a controversial
development that it’s worth re-examining periodically. Let’s restate
the purpose of UAC: It is to allow the user to run the system as a
standard user, not administrator, and still have relatively easy access
to privileged operations when they are necessary.

UAC (click here for Microsoft’s expanded description of it)
is more than that; even when running as administrators, users still run
in a less-privileged context and are warned when privileged operations
are being requested. The way Microsoft sees it, UAC also encompasses
their efforts to make many operations, such as changing system time,
available to standard users.

It’s hard to deny the value of this. The overwhelming majority of
malware currently is delivered through social engineering tricks, such
as opening porn or a greeting card. These should not be privileged
operations, and UAC is a way of taking a time-out and having the user
make sure that a potentially dangerous operation is being performed
deliberately and in an informed manner. The same is true of
vulnerabilities, those of which get past other Vista defenses such as
ASLR and service hardening, which should trigger UAC in a way that
should alert the user. In fact, a recent test of anti-rootkit tools found that UAC popped up and warned as every rootkit in the test tried to execute.

Read the rest of the story on eWEEK.com >> 

 

Recommended for you...

Cork Marks Three Years Linking MSPs to SMB Cyber Resilience
Victoria Durgin
Oct 31, 2025
Amazon Cuts 14,000 Corporate Jobs Amid AI Push
Allison Francis
Oct 29, 2025
Caylent and Trek10 Join Forces in AWS Partner M&A Deal
Allison Francis
Oct 27, 2025
Dataminr and ThreatConnect Join Forces for $290M
Allison Francis
Oct 23, 2025
Channel Insider Logo

Channel Insider combines news and technology recommendations to keep channel partners, value-added resellers, IT solution providers, MSPs, and SaaS providers informed on the changing IT landscape. These resources provide product comparisons, in-depth analysis of vendors, and interviews with subject matter experts to provide vendors with critical information for their operations.

Property of TechnologyAdvice. © 2025 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.