Jump to content

Recommended Posts

Posted

Enabled domain-wide, except on a couple of machines hooked up to cad/cam hardware with idiotic software*.

 

*in theory I could sit down with process explorer and make it play nicely, but the cost/benefit tradeoff isn't worth it.

Posted
Enabled domain-wide, except on a couple of machines hooked up to cad/cam hardware with idiotic software*.

 

*in theory I could sit down with process explorer and make it play nicely, but the cost/benefit tradeoff isn't worth it.

 

LaserCAM drivers per chance?

Posted (edited)
Perfectly serious - plus the likes of SIMS (for example), won't work with it enabled.

 

So for example, if you end up taking registers via SIMS, you need to disable it for every machine otherwise it won't work.

 

I think the argument(s) for UAC are somewhat flawed really. For home users yes, but not in a business/school environment.

 

SIMS works just fine here with UAC enabled.

@mrbios I also fail to see why its disabled.

Edited by FN-GM
Posted

Well, I disabled it a while ago due to an issue but am working back toward having it enabled again.

Problem here is that staff are historically used to a lot of freedom and there is little will from above to change that. But things are slowly being locked down and UAC will make a comeback when everything is fully tested.

Posted
We have it enabled here - if people complain, I explain to them that having a limited user account reduces the risk of virus infection - for most situations limited user account + UAC means that any fun downloaded files they run can only run with their privileges, reducing the attack surface area (and limiting damage).
Posted
Dissabled here. Group Policy stops people doing what they shouldnt be doing.

 

UAC and group policy can't be considered the same thing. That's like saying "i don't need AV, i've got group policy" (no im not comparing UAC to AV either, it's just an example)

Posted

Problem here is that staff are historically used to a lot of freedom and there is little will from above to change that.

 

Our XP machines gave the teacher admin rights over their own laptop! We used to have utorrent etc. all over the place!? When I introduced Windows 7 it was THE opportunity to make them normal users.

 

I put my case to the SMT before hand.

Posted
Our XP machines gave the teacher admin rights over their own laptop! We used to have utorrent etc. all over the place!? When I introduced Windows 7 it was THE opportunity to make them normal users.

 

I put my case to the SMT before hand.

Oh I totally agree, but I guess you managed to get SMT backing right? ;)

Things are changing though.

Posted
No i know that but UAC in most cases will stop people accessing programs it deems as unsuitable for the user.

I just set up policies withing GP to dissalow Certain exe's within a OU.

 

That can be easily by-passed with a little know how.

Posted

Enabled site wide - Old badly maintained software is not my problem, the security of the network however is, besides the only time i EVER see UAC is if I'm at a computer trying to elevate to install/Fix something.

 

besides all of our mis is web based now along with pretty much everything we use, the pcs here are pretty much web browsers and ms office use only now.

Posted
Enabled here and never even considered turning it off - mainly because I've never found any reason to do so. Amazed there is still software that can't deal with it. I like it because if someone needs something installed like a one off plugin or update I can just go their desk and pop an admin password in without having to log them off.
Posted

I am amazed people disable UAC, we haven't found a single application that causes an issue when we upgraded to windows 7 x64 and we have software from as far back as 1998.

 

If you do find an application that does causes an issue you can usually work round it with Microsoft Application Compatibility Toolkit.

Posted

This is what I have to disable UAC (something that was simply ported over from the XP days).

 

What settings do you guys use for UAC?

 

User Account Control: Behavior of the elevation prompt for administrators in Admin Approval Mode Elevate without prompting

User Account Control: Behavior of the elevation prompt for standard users Automatically deny elevation requests

User Account Control: Detect application installations and prompt for elevation Disabled

User Account Control: Only elevate UIAccess applications that are installed in secure locations Enabled

User Account Control: Run all administrators in Admin Approval Mode Disabled

Posted
Enabled everywhere, again can't believe people still shut it off on 2013.

 

Tis the RM way... their stuff doesn't work properly with it on.

Posted

I use these for UAC enabled, with the minimum of annoying messages for end users and admins.

 

User Account Control: Behavior of the elevation prompt for administrators in Admin Approval Mode: Elevate without prompting

User Account Control: Behavior of the elevation prompt for standard users: Automatically deny elevation requests

User Account Control: Virtualize file and registry write failures to per-user locations: Disabled

Posted
I use these for UAC enabled, with the minimum of annoying messages for end users and admins.

 

User Account Control: Behavior of the elevation prompt for administrators in Admin Approval Mode: Elevate without prompting

User Account Control: Behavior of the elevation prompt for standard users: Automatically deny elevation requests

User Account Control: Virtualize file and registry write failures to per-user locations: Disabled

 

Pretty much you have UAC disabled much like I do.

 

I've now also disabled User Account Control: Virtualize file and registry write failures to per-user locations

Posted
Pretty much you have UAC disabled much like I do.

 

I've now also disabled User Account Control: Virtualize file and registry write failures to per-user locations

 

It's not disabled, it's simply *denying* all the elevation requests for normal users, and failing writes when they try to use protected locations like program files. So you get the security for normal users, without the prompts.

Posted
It's not disabled, it's simply *denying* all the elevation requests for normal users, and failing writes when they try to use protected locations like program files. So you get the security for normal users, without the prompts.

 

Sorry, what I meant was that I've set that particular policy to 'disabled' and understand the explnation/reasoning behind it.

 

As good practice goes, it's good to see what others are implementing on their networks.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...