Chipp.in Tech News and Reviews

Windows, Security & Privacy, Open Source and more

Menu
  • Home
  • Windows
  • Security & Privacy
  • Gaming
  • Guides
  • Windows 11 Book
  • Contact
  • RSS Feed
Menu

About Windows 11’s new Administrator protection feature

Posted on November 20, 2024November 20, 2024 by Martin Brinkmann

Microsoft has announced Administrator protection for Windows 11. The new security feature aims to improve security on Windows 11 devices by changing certain actions that require elevation are carried out and handled.

For users, it means that they need to authorize elevated actions using Windows Hello. Depending on how that is set up, it may require entering the device PIN, using biometric authentication, or other means available on the device.

The core changes happen in the background. When a user signs in to Windows, that user is assigned what Microsoft calls a deprivileged user token. When admin privileges are needed, for instance when installing software, Windows will request authorization from the user using Windows Hello.

When the user does so, Windows “uses a hidden, system-generated, profile-separated user account to create an isolated admin token”. This token is “issued to the requesting process and is destroyed once the process ends”.

In other words, the admin privileges do not persist on the system, but end with the execution of the task that requested them.

The following illustration visualizes the process.

Separation of the isolated admin token on Windows 11. source: Microsoft

Microsoft lists the following benefits of Administrator protection:

  • Improved security by requiring explicit authorization for “every administrative task”.
  • Users may manage admin rights by granting or restricting “access granularly to individual apps”.
  • Malware that is designed to acquire administrative privileges silently is blocked.

Managing Administrator protection

Group Policy setting

It appears that Administrator protection is disabled by default. Microsoft explains how administrators may enable the new protection.

It is located under Windows Security > Account protection. There, administrators may toggle Administrator protection to turn the feature on (or off). A restart of the device is required.

There is also a new policy under Computer Configuration > Windows Settings > Security Settings > Local Policies > Security Options.

  • Double-click on User Account Control: Configure type of Admin Approval Mode.
  • Change the Local Security Setting to “Admin Approval Mode with Administrator protection”. This enables the feature.

Closing Words

Administrator protection is an optional feature it appears. This means that it won’t be enabled on most home systems any time soon.

The feature improves security against certain types of malware, but it makes certain operations cumbersome. It remains to be seen how well the Windows 11 community will react to the feature.

Would you enable Administrator protection, if it would be available on your system? Feel free to leave a comment down below.

Tags: windows 11
Category: Windows

Post navigation

← Will Google be forced to sell its Chrome web browser?
WhatsApp finally has an answer for annoying voice messages →

3 thoughts on “About Windows 11’s new Administrator protection feature”

  1. VioletMoon says:
    November 21, 2024 at 12:18 am

    “Malware that is designed to acquire administrative privileges silently is blocked.”

    Sounds like a useful feature, but . . . the rest sounds like “K” in Kafka’s “The Castle” who attempts again and again to gain access to the “mysterious authorities” who govern the village.

    Reply
  2. Tachy says:
    November 21, 2024 at 8:03 am

    Does this apply to systems with only local accounts? Because I don’t use any of those “means available on the device”.

    Also, your words do not match the screenshot.

    There is no “User Account Control: Configure type of Admin Approval Mode.” in the screenshot. In fact it shows a different policy opened.

    In my experiences with actual M.$ employees, they refused to even acknowledge one might not be using a M.$ accout on their own windows PC so it’s no suprise the article you linked to never mentions it and most certainly assumes everyone is happily signed into M.$.

    Reply
  3. Sonya says:
    November 21, 2024 at 1:31 pm

    I purposely do not have any biometric devices on any of my computers, inluding no cameras. So if i understand this correctly it would requie a password or pin to function. Why not just leave it as it is now? This seems to be a solution for something that is not a problem. The more I see what MS is doing to windows. The more and more I am using Linux. I only have one windows system left of 3 computers used, the thers are all Linux.

    Reply

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

  • September 3, 2025 by Martin Brinkmann Google is hunting YouTube Premium Family subscribers now that are not living in the same household
  • August 28, 2025 by Martin Brinkmann Proton launches Emergency Access feature for paid accounts
  • August 27, 2025 by Martin Brinkmann 0Patch promises to keep Microsoft Office 2016 and 2019 secure after official end of support
  • August 26, 2025 by Martin Brinkmann Starting next year, all Android apps need to be registered by verified developers, even sideloaded ones
  • August 24, 2025 by Martin Brinkmann Windows 11: Resuming apps from Android is coming, again

About

We talk, write and dream about Technology 24/7 here at Chipp.in. The site, created by Martin Brinkmann in 2023, focuses on well-researched tech news, reviews, guides, help and more.

Legal Notice

Our commitment

Many websites write about tech, but chipp.in is special in several ways. All of our guides are unique, and we will never just rehash news that you find elsewhere.

Read the About page for additional information on the site and its founder and author.

Support Us

We don't run advertisement on this site that tracks users. If you see ads, they are static links. Ads, including affiliate links, never affect our writing on this site.

Here is a link to our privacy policy

©2025 Chipp.in Tech News and Reviews