How to Configure UAC Administrator Password Prompts with Microsoft Intune
Question details
An organization needs to configure policies requiring standard users to enter administrator credentials when performing elevated tasks (e.g., installing software, running CMD) on cloud-managed devices.

- Product
- Microsoft Intune
- Device & OS
- Windows
- Scenario
- Enforcing standard user UAC elevation credential prompts via cloud management without assigning local administrator rights.
- Observed behavior
- Standard users require a secure prompt for admin credentials instead of being granted elevated local administrator privileges directly.
Ensure you have Microsoft Intune administrator access and that your target Windows devices are successfully enrolled and syncing with the Intune service.
Deploy UAC Credential Prompts via Intune Settings Catalog
Use the Microsoft Intune Settings Catalog to create a configuration profile that enforces UAC password prompts for standard users.
By configuring the Local Policies Security Options within Intune, you can securely enforce UAC prompts without relying on traditional Group Policy Objects (GPOs).
Sign in to the Microsoft Intune admin center. Navigate to 'Devices' > 'Configuration profiles' and select 'Create profile'.
Choose 'Windows 10 and later' as the platform and select 'Settings catalog' for the profile type, then click 'Create'.
Under Configuration settings, click 'Add settings'. Search for 'User Account Control' and locate 'Behavior of the elevation prompt for standard users'.
Check the box for the setting and change its dropdown value to 'Prompt for credentials'. This ensures standard users must enter admin credentials to elevate privileges.
Complete the profile creation wizard by assigning the policy to the appropriate user or device groups, then save and deploy the configuration.

Deploy WPS Office via Intune for Your Organization
While managing device security and policies with Microsoft Intune, consider deploying WPS Office as a lightweight, cost-effective alternative to Microsoft Office. It integrates seamlessly into enterprise environments, offering a familiar UI and broad compatibility.

Frequently Asked Questions
Does UAC in Intune create a single shared administrator password for all users?
No, UAC does not create a shared password for all users. It relies on the credentials of an existing local or organizational administrator account to authenticate the elevation request.
Should I make standard users local administrators to stop UAC prompts?
No. It is highly recommended not to make users local administrators merely to bypass the prompt. Granting local admin rights compromises device security and goes against the principle of least privilege.
Where can I find advanced support for Microsoft Intune configurations?
For detailed Intune guidance and advanced troubleshooting, you can visit the official Microsoft Intune community at techcommunity.microsoft.com.




