logo
search
Security Policy Errors

How to Configure UAC Administrator Password Prompts with Microsoft Intune

Khadija KhanKhadija Khan Sep 28, 2026 869 views

Question details

An organization needs to configure policies requiring standard users to enter administrator credentials when performing elevated tasks (e.g., installing software, running CMD) on cloud-managed devices.

Configure UAC Administrator Password Prompts with Microsoft Intune
Product
Microsoft Intune
Device & OS
Windows
Scenario
Enforcing standard user UAC elevation credential prompts via cloud management without assigning local administrator rights.
Observed behavior
Standard users require a secure prompt for admin credentials instead of being granted elevated local administrator privileges directly.
Before you start

Ensure you have Microsoft Intune administrator access and that your target Windows devices are successfully enrolled and syncing with the Intune service.

Solution 1Recommended

Deploy UAC Credential Prompts via Intune Settings Catalog

Use the Microsoft Intune Settings Catalog to create a configuration profile that enforces UAC password prompts for standard users.

By configuring the Local Policies Security Options within Intune, you can securely enforce UAC prompts without relying on traditional Group Policy Objects (GPOs).

1
Create a new Configuration Profile

Sign in to the Microsoft Intune admin center. Navigate to 'Devices' > 'Configuration profiles' and select 'Create profile'.

2
Select Platform and Profile Type

Choose 'Windows 10 and later' as the platform and select 'Settings catalog' for the profile type, then click 'Create'.

3
Add UAC Settings

Under Configuration settings, click 'Add settings'. Search for 'User Account Control' and locate 'Behavior of the elevation prompt for standard users'.

4
Set the Prompt Behavior

Check the box for the setting and change its dropdown value to 'Prompt for credentials'. This ensures standard users must enter admin credentials to elevate privileges.

5
Assign and Deploy

Complete the profile creation wizard by assigning the policy to the appropriate user or device groups, then save and deploy the configuration.

Deploy UAC Credential Prompts via Intune Settings Catalog
Do Not Grant Local Admin Rights: Do not make users local administrators simply to bypass the UAC prompt. UAC uses credentials for an existing local or organizational administrator account.
Free Microsoft Office alternative

Deploy WPS Office via Intune for Your Organization

While managing device security and policies with Microsoft Intune, consider deploying WPS Office as a lightweight, cost-effective alternative to Microsoft Office. It integrates seamlessly into enterprise environments, offering a familiar UI and broad compatibility.

Fully compatible with Microsoft Word, Excel, and PowerPoint formats.Lightweight installer ideal for mass deployment via Microsoft Intune or endpoint managers.Cost-effective enterprise solution with a highly familiar user interface.Seamless migration for employees without a steep learning curve.
microsoft office alternative - wps office

Frequently Asked Questions

Does UAC in Intune create a single shared administrator password for all users?

No, UAC does not create a shared password for all users. It relies on the credentials of an existing local or organizational administrator account to authenticate the elevation request.

Should I make standard users local administrators to stop UAC prompts?

No. It is highly recommended not to make users local administrators merely to bypass the prompt. Granting local admin rights compromises device security and goes against the principle of least privilege.

Where can I find advanced support for Microsoft Intune configurations?

For detailed Intune guidance and advanced troubleshooting, you can visit the official Microsoft Intune community at techcommunity.microsoft.com.