mrbios Posted November 8, 2013 Posted November 8, 2013 definitely enabled, I'm honestly quite shocked that anyone disables it.
pete Posted November 8, 2013 Posted November 8, 2013 Enabled domain-wide, except on a couple of machines hooked up to cad/cam hardware with idiotic software*. *in theory I could sit down with process explorer and make it play nicely, but the cost/benefit tradeoff isn't worth it.
mrbios Posted November 8, 2013 Posted November 8, 2013 Enabled domain-wide, except on a couple of machines hooked up to cad/cam hardware with idiotic software*. *in theory I could sit down with process explorer and make it play nicely, but the cost/benefit tradeoff isn't worth it. LaserCAM drivers per chance?
FN-GM Posted November 8, 2013 Posted November 8, 2013 (edited) Perfectly serious - plus the likes of SIMS (for example), won't work with it enabled. So for example, if you end up taking registers via SIMS, you need to disable it for every machine otherwise it won't work. I think the argument(s) for UAC are somewhat flawed really. For home users yes, but not in a business/school environment. SIMS works just fine here with UAC enabled. @mrbios I also fail to see why its disabled. Edited November 8, 2013 by FN-GM
Jawloms Posted November 8, 2013 Posted November 8, 2013 SIMS works just fine here with UAC enabled. Can't be! I didn't think SIMS worked "just fine" under any circumstances 1
sparkeh Posted November 8, 2013 Posted November 8, 2013 Well, I disabled it a while ago due to an issue but am working back toward having it enabled again. Problem here is that staff are historically used to a lot of freedom and there is little will from above to change that. But things are slowly being locked down and UAC will make a comeback when everything is fully tested.
Willott Posted November 8, 2013 Posted November 8, 2013 We have it enabled here - if people complain, I explain to them that having a limited user account reduces the risk of virus infection - for most situations limited user account + UAC means that any fun downloaded files they run can only run with their privileges, reducing the attack surface area (and limiting damage).
DannyBroadhurst Posted November 8, 2013 Posted November 8, 2013 Dissabled here. Group Policy stops people doing what they shouldnt be doing.
mrbios Posted November 8, 2013 Posted November 8, 2013 Dissabled here. Group Policy stops people doing what they shouldnt be doing. UAC and group policy can't be considered the same thing. That's like saying "i don't need AV, i've got group policy" (no im not comparing UAC to AV either, it's just an example)
DannyBroadhurst Posted November 8, 2013 Posted November 8, 2013 No i know that but UAC in most cases will stop people accessing programs it deems as unsuitable for the user. I just set up policies withing GP to dissalow Certain exe's within a OU.
chazzy2501 Posted November 8, 2013 Posted November 8, 2013 Problem here is that staff are historically used to a lot of freedom and there is little will from above to change that. Our XP machines gave the teacher admin rights over their own laptop! We used to have utorrent etc. all over the place!? When I introduced Windows 7 it was THE opportunity to make them normal users. I put my case to the SMT before hand.
sparkeh Posted November 8, 2013 Posted November 8, 2013 Our XP machines gave the teacher admin rights over their own laptop! We used to have utorrent etc. all over the place!? When I introduced Windows 7 it was THE opportunity to make them normal users. I put my case to the SMT before hand. Oh I totally agree, but I guess you managed to get SMT backing right? Things are changing though.
FN-GM Posted November 8, 2013 Posted November 8, 2013 No i know that but UAC in most cases will stop people accessing programs it deems as unsuitable for the user. I just set up policies withing GP to dissalow Certain exe's within a OU. That can be easily by-passed with a little know how.
DGardiner Posted November 8, 2013 Posted November 8, 2013 Enabled site wide - Old badly maintained software is not my problem, the security of the network however is, besides the only time i EVER see UAC is if I'm at a computer trying to elevate to install/Fix something. besides all of our mis is web based now along with pretty much everything we use, the pcs here are pretty much web browsers and ms office use only now.
sidewinder Posted November 8, 2013 Posted November 8, 2013 Enabled here and never even considered turning it off - mainly because I've never found any reason to do so. Amazed there is still software that can't deal with it. I like it because if someone needs something installed like a one off plugin or update I can just go their desk and pop an admin password in without having to log them off.
SYNACK Posted November 8, 2013 Posted November 8, 2013 Enabled everywhere, again can't believe people still shut it off on 2013.
apeman Posted November 8, 2013 Posted November 8, 2013 I am amazed people disable UAC, we haven't found a single application that causes an issue when we upgraded to windows 7 x64 and we have software from as far back as 1998. If you do find an application that does causes an issue you can usually work round it with Microsoft Application Compatibility Toolkit.
Chuckster Posted November 11, 2013 Posted November 11, 2013 This is what I have to disable UAC (something that was simply ported over from the XP days). What settings do you guys use for UAC? User Account Control: Behavior of the elevation prompt for administrators in Admin Approval Mode Elevate without prompting User Account Control: Behavior of the elevation prompt for standard users Automatically deny elevation requests User Account Control: Detect application installations and prompt for elevation Disabled User Account Control: Only elevate UIAccess applications that are installed in secure locations Enabled User Account Control: Run all administrators in Admin Approval Mode Disabled
X-13 Posted November 11, 2013 Posted November 11, 2013 Enabled everywhere, again can't believe people still shut it off on 2013. Tis the RM way... their stuff doesn't work properly with it on.
DMcCoy Posted November 11, 2013 Posted November 11, 2013 I use these for UAC enabled, with the minimum of annoying messages for end users and admins. User Account Control: Behavior of the elevation prompt for administrators in Admin Approval Mode: Elevate without prompting User Account Control: Behavior of the elevation prompt for standard users: Automatically deny elevation requests User Account Control: Virtualize file and registry write failures to per-user locations: Disabled
Chuckster Posted November 11, 2013 Posted November 11, 2013 I use these for UAC enabled, with the minimum of annoying messages for end users and admins. User Account Control: Behavior of the elevation prompt for administrators in Admin Approval Mode: Elevate without prompting User Account Control: Behavior of the elevation prompt for standard users: Automatically deny elevation requests User Account Control: Virtualize file and registry write failures to per-user locations: Disabled Pretty much you have UAC disabled much like I do. I've now also disabled User Account Control: Virtualize file and registry write failures to per-user locations
DMcCoy Posted November 11, 2013 Posted November 11, 2013 Pretty much you have UAC disabled much like I do. I've now also disabled User Account Control: Virtualize file and registry write failures to per-user locations It's not disabled, it's simply *denying* all the elevation requests for normal users, and failing writes when they try to use protected locations like program files. So you get the security for normal users, without the prompts.
Chuckster Posted November 11, 2013 Posted November 11, 2013 It's not disabled, it's simply *denying* all the elevation requests for normal users, and failing writes when they try to use protected locations like program files. So you get the security for normal users, without the prompts. Sorry, what I meant was that I've set that particular policy to 'disabled' and understand the explnation/reasoning behind it. As good practice goes, it's good to see what others are implementing on their networks.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now