Learning To Love UAC

User Access Control in Windows Vista has been such a controversial development that it’s worth re-examining periodically. Let’s restate the purpose of UAC: It is to allow the user to run the system as a standard user, not administrator, and still have relatively easy access to privileged operations when they are necessary. UAC (click here […]

Written By: Larry Seltzer
Jun 4, 2008
Channel Insider content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

User
Access Control in Windows Vista has been such a controversial
development that it’s worth re-examining periodically. Let’s restate
the purpose of UAC: It is to allow the user to run the system as a
standard user, not administrator, and still have relatively easy access
to privileged operations when they are necessary.

UAC (click here for Microsoft’s expanded description of it)
is more than that; even when running as administrators, users still run
in a less-privileged context and are warned when privileged operations
are being requested. The way Microsoft sees it, UAC also encompasses
their efforts to make many operations, such as changing system time,
available to standard users.

It’s hard to deny the value of this. The overwhelming majority of
malware currently is delivered through social engineering tricks, such
as opening porn or a greeting card. These should not be privileged
operations, and UAC is a way of taking a time-out and having the user
make sure that a potentially dangerous operation is being performed
deliberately and in an informed manner. The same is true of
vulnerabilities, those of which get past other Vista defenses such as
ASLR and service hardening, which should trigger UAC in a way that
should alert the user. In fact, a recent test of anti-rootkit tools found that UAC popped up and warned as every rootkit in the test tried to execute.

Read the rest of the story on eWEEK.com >> 

 

Recommended for you...

MinIO Debuts Academy With AI Partner Enablement

MinIO launches MinIO Academy to train IT pros and partners on AIStor, delivering expert-led courses for AI-driven object storage mastery.

Jordan Smith
Aug 18, 2025
Concentric AI Adds Integrations to Data Governance Platform

Concentric AI adds Wiz, Salesforce, and GitHub integrations to boost Semantic Intelligence platform’s AI-driven data governance and security capabilities.

Jordan Smith
Aug 15, 2025
Brivo Launching New Solution to Boost Security Suite

Brivo and Envoy partner to unify access control & visitor management, delivering scalable, compliant, and secure workplace experiences.

Jordan Smith
Aug 13, 2025
GitHub CEO Steps Down as Microsoft Tightens AI Integration

GitHub CEO Thomas Dohmke to step down in 2025 as Microsoft moves platform into CoreAI, deepening its role in the company’s AI development strategy.

Allison Francis
Aug 13, 2025
Channel Insider Logo

Channel Insider combines news and technology recommendations to keep channel partners, value-added resellers, IT solution providers, MSPs, and SaaS providers informed on the changing IT landscape. These resources provide product comparisons, in-depth analysis of vendors, and interviews with subject matter experts to provide vendors with critical information for their operations.

Property of TechnologyAdvice. © 2025 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.