edutech4schools Posted November 7, 2013 Posted November 7, 2013 I look after a few primary schools and a few years back I disabled UAC using Group Policies as I was getting fed up of users always asking me to type my password in so they could run stuff. Is this the norm or am I on my own in disabling UAC? Should I enable it? and if so how do you cut down on the message boxes that get presented to the user. I have also noticed that on my new Windows 8 laptop you need UAC enabled to use the app store.
Michael Posted November 7, 2013 Posted November 7, 2013 I disable it domain wide. There's no need for it in a managed environment.
localzuk Posted November 7, 2013 Posted November 7, 2013 Not disabled it here. Too useful to turn off. Properly managed, staff never come across it anyway.
zag Posted November 7, 2013 Posted November 7, 2013 Disabled Domain wide, totally stupid decision by microsoft to design it that way. Just gets annoying rather than helping.
chazzy2501 Posted November 7, 2013 Posted November 7, 2013 UAC is super useful. Make it work for you. It never upsets my staff unless they try and install utorrent or iTunes... 1
3s-gtech Posted November 7, 2013 Posted November 7, 2013 Enabled domain wide - extra level of protection, works well for us. Never found it gets in the way, but it does stop people doing things they're not supposed to, where XP was totally happy to let them stuff it.
hardtailstar Posted November 7, 2013 Posted November 7, 2013 Disabled on domain but stand alones still have it.
Firefox Posted November 7, 2013 Posted November 7, 2013 Enabled here....the only people it annoys are the IT admins as we have a legitimate need to elevate, but we can live with this. Has caused a few issues with other applications we try to run remotely and get blocked because of UAC, but as soon as we understood this, was easy enough to work around.
RichCowell Posted November 7, 2013 Posted November 7, 2013 Left it enabled here on all machines apart from the finance machines as it causes trouble running one of the apps they use...
edutech4schools Posted November 7, 2013 Author Posted November 7, 2013 Thanks. Bit of a mixed bag so far. If enabled how do you stop UAC popping up and asking for standard things like adding a printer or updating java.
localzuk Posted November 7, 2013 Posted November 7, 2013 Thanks. Bit of a mixed bag so far. If enabled how do you stop UAC popping up and asking for standard things like adding a printer or updating java. Group Policy deals with printer related stuff. Updating Java is done centrally, not by staff (along with all software).
Firefox Posted November 7, 2013 Posted November 7, 2013 Thanks. Bit of a mixed bag so far. If enabled how do you stop UAC popping up and asking for standard things like adding a printer or updating java. Likewise we centrally deploy software to have control over what is out there. For printing, this is done via the point and print restrictions Allowing Standard Users to Install Network Printers on Windows 7 without Prompting for Administrative Credentials - GES on Windows 7 - Site Home - MSDN Blogs
edutech4schools Posted November 7, 2013 Author Posted November 7, 2013 For printing, this is done via the point and print restrictions Allowing Standard Users to Install Network Printers on Windows 7 without Prompting for Administrative Credentials - GES on Windows 7 - Site Home - MSDN Blog Thanks.
Arthur Posted November 7, 2013 Posted November 7, 2013 I disable it domain wide. There's no need for it in a managed environment. You can't be serious? UAC does more than display popup boxes.
Michael Posted November 7, 2013 Posted November 7, 2013 Perfectly serious - plus the likes of SIMS (for example), won't work with it enabled. So for example, if you end up taking registers via SIMS, you need to disable it for every machine otherwise it won't work. I think the argument(s) for UAC are somewhat flawed really. For home users yes, but not in a business/school environment.
Theblacksheep Posted November 7, 2013 Posted November 7, 2013 (edited) Perfectly serious - plus the likes of SIMS (for example), won't work with it enabled. So for example, if you end up taking registers via SIMS, you need to disable it for every machine otherwise it won't work. I think the argument(s) for UAC are somewhat flawed really. For home users yes, but not in a business/school environment. SIMS works fine with UAC enabled. Its enabled domain wide here, no reason not to have it on. Updating SIMS via Solus2 doesn't because it tried to put files in the places Microsoft have not supported for 20 years, but that's Capita's fault. Edited November 7, 2013 by Theblacksheep
john Posted November 7, 2013 Posted November 7, 2013 I had it enabled domain wide as others have said it adds an extra level of protection which is good
chazzy2501 Posted November 7, 2013 Posted November 7, 2013 I use SIMS with UAC it runs and updates fine. Point and print restrictions work great for adding printers and installing their drivers from the print server. All users run as standard domain users, all admin tasks prompt for admin login, which is handy.
Arthur Posted November 7, 2013 Posted November 7, 2013 I use SIMS with UAC it runs and updates fine. Point and print restrictions work great for adding printers and installing their drivers from the print server. All users run as standard domain users, all admin tasks prompt for admin login, which is handy. Ditto!
AngryTechnician Posted November 7, 2013 Posted November 7, 2013 Have always left it on domain-wide except on our MIS server, as the MIS software requires it to be off. Other than that I have never seen a single issue.
sted Posted November 7, 2013 Posted November 7, 2013 generally on pcs on servers (pre 2012) off (im an admin i shouldnt need uac to stop me doing something dumb) and the odd pc where for reasons of software its off
free780 Posted November 8, 2013 Posted November 8, 2013 (edited) Enable but without prompting for users. Admins have to right click run as admin. I installing updating applications, printers is not a issue when using the system account. I wouldnt have it disabled as it turns off ie protected mode. If it causes application issues you need to grant modify rights to the users who need it. We did have disable the folder redirection for 1 application. UAC only prompts for changes to program files ( inc x86 on 64bit) the windows folder or the machine registry. You just have to do the modify rights. Never had to change permission on the mahine registry. A lot of our software is gpo/script. Edited November 8, 2013 by free780
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now