Microsoft has announced Administrator protection for Windows 11. The new security feature aims to improve security on Windows 11 devices by changing certain actions that require elevation are carried out and handled.
For users, it means that they need to authorize elevated actions using Windows Hello. Depending on how that is set up, it may require entering the device PIN, using biometric authentication, or other means available on the device.
The core changes happen in the background. When a user signs in to Windows, that user is assigned what Microsoft calls a deprivileged user token. When admin privileges are needed, for instance when installing software, Windows will request authorization from the user using Windows Hello.
When the user does so, Windows “uses a hidden, system-generated, profile-separated user account to create an isolated admin token”. This token is “issued to the requesting process and is destroyed once the process ends”.
In other words, the admin privileges do not persist on the system, but end with the execution of the task that requested them.
The following illustration visualizes the process.

Microsoft lists the following benefits of Administrator protection:
- Improved security by requiring explicit authorization for “every administrative task”.
- Users may manage admin rights by granting or restricting “access granularly to individual apps”.
- Malware that is designed to acquire administrative privileges silently is blocked.
Managing Administrator protection

It appears that Administrator protection is disabled by default. Microsoft explains how administrators may enable the new protection.
It is located under Windows Security > Account protection. There, administrators may toggle Administrator protection to turn the feature on (or off). A restart of the device is required.
There is also a new policy under Computer Configuration > Windows Settings > Security Settings > Local Policies > Security Options.
- Double-click on User Account Control: Configure type of Admin Approval Mode.
- Change the Local Security Setting to “Admin Approval Mode with Administrator protection”. This enables the feature.
Closing Words
Administrator protection is an optional feature it appears. This means that it won’t be enabled on most home systems any time soon.
The feature improves security against certain types of malware, but it makes certain operations cumbersome. It remains to be seen how well the Windows 11 community will react to the feature.
Would you enable Administrator protection, if it would be available on your system? Feel free to leave a comment down below.









