25H2 Feature Focus: Administrator Protection (Premium)

Windows 11 version 25H2 will ship with a major security advance called Administrator Protection. Depending on how you use the PC, it could be disruptive.
❓ Why?
It’s not worth going through the entire convoluted history of user accounts in Windows, but the big milestones there are Windows NT, the transition to the NT code base for mainstream users in Windows XP, User Account Control (UAC), which debuted in Windows Vista, and then the ability to sign in to Windows using an online account, beginning with Windows 8.

Along the way, PCs became more secure with Trusted Platform Module (TPM) security chips, biometric authentication via Windows Hello, and then end-to-end security guarantees with the Copilot+ PC platform and Windows Hello Enhanced Sign-In Security (ESS).

Through all this, the advice to individuals has remained largely unchanged: Though the first account you create on a Windows PC will always be an administrator account with its associated elevated privileges, you should always create a second account with standard user privileges and use that account day-to-day.

Also largely unchanged over those decades: Almost no one does that.

Microsoft has tried all kinds of things to combat the risks associated with signing in to Windows with an admin account. UAC is perhaps the most obvious because it was initially so disruptive, but initiatives like the Metro/Modern app platform and S mode should also be viewed as part of this work. And Microsoft also took many smaller steps to basically protect users from themselves.

But none of it worked. And as the Secure Future Initiative (SFI) begat the Windows Resiliency Initiative, Microsoft introduced a coming Windows 11 feature that might actually solve the problem. It’s called Administrator Protection.
? Why not just improve UAC?
We’ve been using UAC for so long now that many of us probably forget about the problem that it tried to solve: Previous to Windows Vista, all apps and services that ran while an admin user was signed in ran with (elevated) administrator privileges. With UAC, most apps and some services run with standard user privileges even if the signed-in user is an admin. And apps are given a virtualized copies of the file system and registry. If an app or service requires elevation, the user is shown a UAC prompt that appears modally over the rest of the desktop in a special Secure Desktop mode.

In the language of the day, UAC was all about “reducing the attack surface,” because reducing the privileges afforded to most apps and services helps protect against electronic attack. If your system is compromised by a worm, Trojan, virus, or other form of malware, that malicious code then runs with administrator privileges as well. That's how PCs get "owned." In more recent years, I’ve likened UAC to the middle, third brake light on automobiles: It’s an additional warning, in this case that you’re about to do something potentially dangerous. But it also happens...

Gain unlimited access to Premium articles.

With technology shaping our everyday lives, how could we not dig deeper?

Thurrott Premium delivers an honest and thorough perspective about the technologies we use and rely on everyday. Discover deeper content as a Premium member.

Tagged with

Share post

Thurrott