Blog / Coding tips

What Is UAC in Windows? User Account Control Explained for Beginners

Cover image for What Is UAC in Windows? User Account Control Explained for Beginners

UAC (User Account Control) is the Windows security feature that makes even administrator accounts run programs with standard user rights, and asks you to approve or supply a password before anything gets full admin power. That’s the “Do you want to allow this app to make changes to your device?” box. It exists to stop malware from silently getting administrator privileges, and Microsoft ships it switched on by default.

I’m learning Windows security alongside web development, and UAC was one of the first things that confused me. Why does an admin account still get asked? Why does the whole screen go dark? Is turning it off a sensible shortcut? This guide answers those questions using Microsoft’s own documentation, checked on 11 October 2026, and avoids the scary jargon where possible.

What UAC actually does

Microsoft describes UAC as a feature that “protects the operating system from unauthorized changes”. When a change needs administrator permission, UAC notifies you and gives you the chance to approve or deny it. The important idea is least privilege: programs only get the rights they need, and only when you agree.

Without UAC, any program you start from an admin account would inherit full control of the machine. A dodgy download, a malicious macro or a compromised browser extension could install drivers, change system files or disable your antivirus without asking. UAC puts a speed bump in that path. Malware still has to trick you into clicking Yes, and that’s a much harder job than running quietly in the background.

UAC also protects itself. Microsoft notes that, unless you disable UAC, malicious software is prevented from disabling or interfering with UAC settings. You need admin rights to change how it behaves.

How UAC works: one account, two access tokens

When you sign in, Windows creates an access token: a small bundle of data that says who you are, which groups you belong to and which privileges you hold. Every program you start carries a copy of that token, and Windows checks it whenever the program tries to open a file, change a setting or talk to another process.

Here’s the clever bit. According to Microsoft’s explanation of how UAC works, when an administrator signs in, Windows creates two tokens:

  • A standard user access token, with the administrative privileges and group SIDs removed.
  • An administrator access token, with everything.

Windows uses the standard token to start explorer.exe, the desktop shell. Because almost every program you launch is a child of Explorer, they all inherit the standard token too. So your browser, your email client and that random installer all start with ordinary rights, even though your account is technically an admin.

Only when a program asks for admin rights does UAC step in, show a prompt, and (if you agree) start that one program with the full administrator token. Microsoft calls this setup Admin Approval Mode.

Integrity levels

Windows also tags each process with an integrity level, a measure of trust. A disk partitioning tool that changes system data runs at high integrity. A web browser, which handles untrusted content all day, runs at a lower level. A process with a lower integrity level can’t modify a process with a higher one. That’s one reason a compromised browser tab can’t simply reach into an elevated admin tool.

The consent prompt vs the credential prompt

You’ll see one of two prompts, depending on what kind of account you’re using.

  • Who sees it: Consent prompt: Members of the Administrators group; Credential prompt: Standard users (by default).
  • What it asks: Consent prompt: Click Yes or No; Credential prompt: Type an administrator’s user name and password.
  • What happens on Yes: Consent prompt: The app runs with your admin token; Credential prompt: The app runs with that admin account’s token.

The consent prompt is what most home users know, because the first account on a new PC is usually an administrator. The credential prompt appears when you’re signed in as a standard user and something needs admin rights. In that case, typing your own password won’t help; you need the details of an account that’s in the Administrators group.

Microsoft’s own recommendation is that “your primary user account is a standard user”. Running day to day as a standard user means a malicious program can’t even get a Yes-click elevation from you; it needs a password you’d have to type deliberately.

Why the UAC prompt is grey or yellow

The colour of the banner tells you something about the program asking for permission. Before showing the prompt, Windows checks the executable’s digital signature:

  • Grey banner: a Windows administrative app, such as a Control Panel item, or a program signed by a verified publisher.
  • Yellow banner: the program is unsigned, or it’s signed but not trusted.

A yellow prompt isn’t automatically evil. Plenty of small, legitimate tools are unsigned. But it is a cue to slow down. Ask yourself: did I just start this? Do I know where it came from? Is the program name what I expected? If a yellow prompt appears out of nowhere while you’re browsing, click No.

The shield icon

You’ve probably seen a small blue-and-yellow shield on certain buttons in Windows. It marks an action that needs admin rights. Microsoft’s example is the Date and Time settings: a standard user can change the time zone freely, but changing the system clock itself requires a full administrator token, so that button carries the shield.

The secure desktop: why your screen goes dark

When a UAC prompt appears, the rest of the screen dims and you can’t click anything else. That isn’t just a visual effect. Windows has switched to the secure desktop, a separate desktop that only Windows processes can access.

The point is to stop other programs from tampering with the prompt. On the normal (interactive) desktop, a malicious program could try to send fake mouse clicks to the Yes button, or draw something over the prompt to mislead you. On the secure desktop, ordinary programs simply can’t reach the prompt. Microsoft recommends keeping the Switch to the secure desktop when prompting for elevation policy enabled, and it’s enabled by default. Since Windows Server 2019, you also can’t paste clipboard content onto the secure desktop, and the same applies to supported Windows client versions.

Malware can draw an imitation of the dimmed screen, but Microsoft points out that with the default consent behaviour it doesn’t gain elevation even if you click Yes on the fake. The real risk is a fake credential prompt that harvests a password, which is another reason to only type admin passwords when you started the action yourself.

The four UAC slider levels

To see your current setting, open the Start menu, type UAC and choose Change User Account Control settings. You’ll see a slider with four positions. The descriptions below follow Microsoft’s UAC architecture documentation.

  • Always notify: prompts when apps make changes and when you change Windows settings; dims the desktop.
  • Notify me only when apps try to make changes (default): prompts for apps but not for your own settings changes; dims the desktop.
  • Notify me only when apps try to make changes (do not dim my desktop): same prompts as the default, but no dimming.
  • Never notify: no prompts and no dimming.

Always notify is the strictest level. Microsoft suggests it if you often install new software or visit unfamiliar websites. You’ll see more prompts, including when you open built-in admin tools.

The default level prompts when programs try to install software or change your computer, but not when you change Windows settings yourself. It still uses the secure desktop. For most people, this is the right balance.

The “do not dim” level shows the prompt on your normal desktop. Microsoft doesn’t recommend it and says to choose it only if dimming takes a long time on your computer. You lose the secure desktop protection described above.

Never notify doesn’t fully switch UAC off, which surprises many people. The UAC service keeps running, elevation requests from administrators are approved automatically with no prompt, and elevation requests from standard users are automatically denied. Microsoft labels this option “not recommended due to security concerns”.

Where UAC settings live: policies and the registry

The slider is a friendly front end for a set of security policies. On Pro, Enterprise and Education editions you can see them in the Local Security Policy console (secpol.msc) under Security Settings › Local Policies › Security Options; every one starts with “User Account Control:”. Behind those policies are registry values under this key:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System

These are the values beginners most often run into, with the defaults taken from Microsoft’s UAC settings reference:

  • EnableLUA (default 1, enabled): Run all administrators in Admin Approval Mode, the master switch.
  • ConsentPromptBehaviorAdmin (default 5): What admins see: 0 = elevate without prompting, 1 = credentials on secure desktop, 2 = consent on secure desktop, 3 = credentials, 4 = consent, 5 = consent for non-Windows binaries.
  • ConsentPromptBehaviorUser (default 3): What standard users see: 0 = automatically deny, 1 = credentials on secure desktop, 3 = credentials.
  • PromptOnSecureDesktop (default 1, enabled): Show prompts on the secure desktop.
  • FilterAdministratorToken (default 0, disabled): Admin Approval Mode for the built-in Administrator account.
  • EnableVirtualization (default 1, enabled): Redirect failed writes from old apps to per-user locations.

You can read these safely in PowerShell without changing anything:

Get-ItemProperty 'HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System' |
  Select-Object EnableLUA, ConsentPromptBehaviorAdmin, ConsentPromptBehaviorUser, PromptOnSecureDesktop

Notice that the default for admins, value 5, means “prompt for consent for non-Windows binaries”. That’s why some built-in Windows tools open without a prompt at the default slider level, while third-party installers always ask.

The built-in Administrator account is different

Windows has a hidden account literally called Administrator. By default, FilterAdministratorToken is 0, which means that account does not use Admin Approval Mode: it runs every program with full admin rights and no prompts. It’s disabled on normal installs for good reason. If a tutorial tells you to enable it and use it as your daily account, don’t.

File and registry virtualisation

Some older programs assume they could write to protected folders such as C:\Program Files or C:\Windows. Under UAC those writes would fail. To keep such apps working, Windows can quietly redirect the failed writes to per-user locations instead. Microsoft lists the protected locations as %ProgramFiles%, %Windir%, %Windir%\system32 and HKLM\Software.

This is the Virtualize file and registry write failures to per-user locations policy, and it’s on by default. If you’ve ever “saved” a settings file into Program Files and then couldn’t find it later, virtualisation is a likely reason. If those %Windir% style names look unfamiliar, they’re environment variables, a topic I’ll cover separately.

Should you turn UAC off?

No. It’s tempting when an old game or tool keeps prompting, but the trade-off is poor:

  • With EnableLUA disabled, every program you start from an admin account runs with full admin rights, which is exactly the situation UAC was built to prevent.
  • Microsoft notes that if you disable Admin Approval Mode, Windows Security warns you that the overall security of the operating system is reduced.
  • Microsoft also warns that some Universal Windows Platform apps might not work when UAC is fully disabled.

Better fixes for annoying prompts:

  1. Right-click › Run as administrator only for the specific tool that needs it.
  2. Update or replace old software that writes to protected folders.
  3. Use a standard account day to day and keep a separate admin account for installs. The extra password step makes you think before granting power.
  4. If you’re a developer, install tools per-user (many installers offer a “just for me” option) so they don’t need elevation.

The same least-privilege thinking applies when you build software: give each part only the access it needs, and handle credentials carefully, for example by hashing passwords properly in PHP rather than storing them as plain text.

UAC is not a security boundary (and why that matters)

If you start reading about Windows security, you’ll come across the term UAC bypass: a technique that gets elevated rights without showing a prompt. In Microsoft’s Windows Security Servicing Criteria, UAC is listed as a security feature, not a security boundary, and Microsoft doesn’t commit to fixing UAC bypasses as security vulnerabilities by default. That’s another strong argument for running as a standard user: there’s nothing to bypass from a standard account if the attacker doesn’t know an admin password.

For a beginner, the practical lesson is simple. UAC reduces risk a lot, but it relies on you. If you click Yes to everything, it can’t help. Read the program name and publisher, and if you didn’t start the action, say no.

How to check UAC is working on your PC

A quick health check you can do in under a minute:

  1. Open Change User Account Control settings and confirm the slider is on the default level or higher.
  2. Right-click Command Prompt or Terminal and choose Run as administrator. You should see a prompt on a dimmed screen.
  3. Run whoami /groups in a normal (non-elevated) window and look for a line containing Mandatory Label\Medium Mandatory Level. In the elevated window, the same command shows High Mandatory Level. That difference is UAC’s split token in action.
  4. Open Settings › Accounts › Your info and check whether your everyday account says Administrator. If it does, consider creating a standard account for daily use.

FAQ

What does UAC stand for in Windows?

UAC stands for User Account Control. It’s the Windows feature that runs programs with standard user rights and asks for consent or an administrator password before a program gets full admin privileges.

Why does Windows ask for permission when I’m an administrator?

Because an administrator account gets two access tokens at sign-in. Windows runs your programs with the restricted standard token and only uses the full admin token after you approve a UAC prompt. This is called Admin Approval Mode.

Why does my screen go dark when a UAC prompt appears?

Windows switches to the secure desktop, which only Windows processes can access. Other programs can’t click or draw over the prompt, so malware can’t approve the request for you.

Is it safe to set UAC to Never notify?

No. Microsoft says this level isn’t recommended because of security concerns. Programs started by administrators get elevated automatically without asking, and standard users’ elevation requests are silently denied.

What is the difference between a yellow and a grey UAC prompt?

A grey prompt means the program is a Windows administrative app or is signed by a verified publisher. A yellow prompt means the program is unsigned or its signature isn’t trusted, so take extra care before clicking Yes.

How do I fully disable UAC?

The slider can’t do it; you’d have to disable the “Run all administrators in Admin Approval Mode” policy (the EnableLUA registry value). It isn’t recommended: it removes a key protection and can stop some Windows apps working.

Does UAC protect a standard user account?

Yes. A standard user sees a credential prompt and needs an administrator’s user name and password to elevate. Microsoft recommends using a standard account as your main account for this reason.

// note

How to read this note.

This is a learning note from studying the web. It is one small topic, written so I can remember it. It is not a course and not a claim that I have finished the subject.

If a sentence is wrong, say so from the contact page and name this title. Drafts never appear here. Related notes, when they exist, are other published posts, and the same sample rule applies to each of them.

Related posts

NTFS vs FAT32 vs exFAT: Which Format Should You Use? (Windows 2026)
Coding tips

NTFS vs FAT32 vs exFAT: Which Format Should You Use? (Windows 2026)

Use NTFS for internal Windows drives, exFAT for USB sticks and SD cards you share with a Mac, and FAT32 only for small or old devices. Here are the real limits (4 GB files, 32 GB format cap), the security differences and the commands.

October 11, 2026 · 12 min read · 0 views

What Is %windir%? Windows Environment Variables Explained (With a List)
Coding tips

What Is %windir%? Windows Environment Variables Explained (With a List)

%windir% is an environment variable that points to the Windows folder, usually C:\Windows. Here’s what the common variables mean, the difference between user and system variables, set vs setx, PowerShell’s $Env: syntax and how PATH finds programs.

October 11, 2026 · 11 min read · 1 view

Python enumerate(): How to Start at 1 (and 12 Tested Examples)
Coding tips

Python enumerate(): How to Start at 1 (and 12 Tested Examples)

enumerate(items, start=1) gives you a counter that starts at 1 alongside each item. Tested examples for lists, dicts, zip, reversed order, file line numbers and comprehensions, plus why it beats range(len()) and the list.index() trap.

October 11, 2026 · 11 min read · 0 views

PHP Sort Multidimensional Array by Value (usort, Tested)
Coding tips

PHP Sort Multidimensional Array by Value (usort, Tested)

usort($rows, fn($a, $b) => $a['grade'] <=> $b['grade']) sorts by one column. Descending, several columns, UK dates, case-insensitive names, keeping keys and array_multisort.

October 7, 2026 · 17 min read · 13 views