L1BIO 09.02.03ISO A.9.2.3CIS Windows - UAC standard user
Intune: UAC Elevation Prompt For Standard Users
π 2025-10-30
β’
β±οΈ 3 minuten lezen
β’
π΄ Must-Have
πΌ Management Samenvatting
UAC elevation prompt voor standard users = require ADMIN credentials voor privileged operations - standard users CANNOT elevate without admin password.
Aanbeveling
IMPLEMENT
Risico zonder
High
Risk Score
8/10
Implementatie
3u (tech: 1u)
Van toepassing op:
β Windows 10 β Windows 11
Standard users = least privilege: Principle: Daily work = standard user (no admin rights), Privileged operations: Software install, system changes β require admin credentials. UAC voor standard users: Malware scenario: User browses β malware download β elevation required β UAC: 'Enter admin password', Standard user: NO admin password β CANNOT elevate β malware blocked. Defense: Malware cannot silently gain admin rights (unlike 'elevate without prompting').
PowerShell Modules Vereist
Primary API: Microsoft Graph API Connection:Connect-MgGraph Required Modules: Microsoft.Graph.DeviceManagement
Implementatie
UAC standard user modes: 'Automatically deny': NO elevation (strongest - maar blocks legitimate admin tasks), 'Prompt for credentials': Ask admin username + password (AANBEVOLEN), 'Prompt for credentials on secure desktop': Isolated prompt (BEST - prevents credential theft). Best practice: 'Prompt for credentials on secure desktop' (admin must provide credentials, isolated session).
Vereisten
Intune subscription
Windows 10/11
Users: Standard user accounts (NOT local admin)
Helpdesk: Admin credentials available
Implementatie
Intune Settings Catalog: Local Policies Security Options β User Account Control: Behavior of De elevation prompt for standard users: 'Prompt for credentials on De secure desktop'.
Compliance
CIS Windows Benchmark L1, Microsoft Security Baseline, BIO 09.02, ISO 27001 A.9.2.3.
Monitoring
Gebruik PowerShell-script elevation-prompt-standard-users.ps1 (functie Invoke-Monitoring) β Controleren.
Remediatie
Gebruik PowerShell-script elevation-prompt-standard-users.ps1 (functie Invoke-Remediation) β Herstellen.
Compliance & Frameworks
CIS M365: Control Windows - UAC standard user (L1) -
BIO: 09.02.03 -
ISO 27001:2022: A.9.2.3 -
Automation
Gebruik het onderstaande PowerShell script om deze security control te monitoren en te implementeren. Het script bevat functies voor zowel monitoring (-Monitoring) als remediation (-Remediation).