Saturday, November 21, 2009

How can I disable the User Account Control (UAC) feature on my Windows Vista computer?

Windows Vista has the built-in ability to automatically reduce the potential of security breaches in the system. It does that by automatically enabling a feature called User Account Control (or UAC for short). The UAC forces users that are part of the local administrators group to run like they were regular users with no administrative privileges.


Method #1 - Using MSCONFIG

  1. Launch MSCONFIG by from the Run menu.
  2. Click on the Tools tab. Scroll down till you find "Disable UAC" . Click on that line.
    MSCONFIG - Disable Account Protection
  3. Press the Launch button.
  4. A CMD window will open. When the command is done, you can close the window.
  5. Close MSCONFIG. You need to reboot the computer for changes to apply.

You can re-enable UAC by selecting the "Enable UAC" line and then clicking on the Launch button.

*Recommended: Speed up Vista boot times by reducing the number of programs that load at startup. Control your Vista startup list with this Vista app

Method #2 - Using Regedit

  1. Open Registry Editor.
  2. In Registry Editor, navigate to the following registry key:
    HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System
  3. Locate the following value (DWORD): EnableLUA and give it a value of 0.
    Regedit - Disable UAC
  4. Note: As always, before making changes to your registry you should always make sure you have a valid backup. In cases where you're supposed to delete or modify keys or values from the registry it is possible to first export that key or value(s) to a .REG file before performing the changes.

  5. Close Registry Editor. You need to reboot the computer for changes to apply.

In order to re-enable UAC just change the above value to 1.

Method #3 - Using Group Policy

This can be done via Local Group Policy or via Active Directory-based GPO, which is much more suited for large networks where one would like to disable UAC for many computers at once.

If using Local Group Policy you'll need to open the Group Policy Editor (Start > Run > gpedit.msc) from your Vista computer.

If using in AD-based GPO, open Group Policy Management Console (Start > Run > gpmc.msc) from a Vista computer that is a member of the domain. In the GPMC window, browse to the required GPO that is linked to the OU or domain where the Vista computers are located, then edit it.

  1. In the Group Policy Editor window, browse to Computer Configuration > Windows Settings > Security Settings > Local Policies > Security Options.
    Group Policy - Disable UAC
  2. In the right pane scroll to find the User Access Control policies (they're down at the bottom of the window). You need to configure the following policies:Group Policy - Disable UAC
  3. You'll need to reboot your computers.

Method #4 - Using Control Panel

  1. Open Control Panel.
  2. Under User Account and Family settings click on the "Add or remove user account".
    Add or remove user account
  3. Click on one of the user accounts, for example you can use the Guest account.
  4. Under the user account click on the "Go to the main User Account page" link.
    Go to the Main User Accounts Page
  5. Under "Make changes to your user account" click on the "Change security settings" link.
    Change security settings
  6. In the "Turn on User Account Control (UAC) to make your computer more secure" click to unselect the "Use User Account Control (UAC) to help protect your computer". Click on the Ok button.
    Turn on AUC
  7. You will be prompted to reboot your computer. Do so when ready.
    Disable UAC - Reboot

In order to re-enable UAC just select the above checkbox and reboot.

No comments:

Post a Comment