Hide Administrator Account From UAC Prompt in Windows 10

User Account Control, or just UAC is a part of the Windows security system which prevents apps from making unwanted changes on your PC. By default, the UAC prompt shows administrative accounts which can be selected by standard users to elevate a program. For extra security, you can hide administrative accounts from that dialog, so standard users have to additionally enter valid credentials for a local administrator account including a user name and password.

Since Windows Vista, Microsoft added a new security feature called User Account Control (UAC). It tries to prevent malicious apps from doing potentially harmful things on your PC. When some software tries to change system-related parts of the Registry or the file system, Windows 10 shows an UAC confirmation dialog, where the user should confirm if he really wants to make those changes. Usually, the apps that require elevation are related to the management of Windows or your computer in general. A good example would be the Registry Editor app.

Power Option Context Menu Confirm UAC Prompt

The UAC comes with different security levels. When its options are set to Always notify or Default, your Desktop will be dimmed. The session will be temporary switched to the secure Desktop without open windows and icons, containing only an elevation prompt by the User Account Control (UAC).

Members of the Administrators user group have to confirm or reject the UAC prompt without providing extra credentials (UAC consent prompt). Users without administrative privileges have to additionally enter valid credentials for a local administrator account (UAC credential prompt).

There is a special security policy in Windows 10 that allows hiding the available local administrative accounts from a UAC prompt.

A UAC prompt for a standard user account with its default options looks as follows.

Windows 10 UAC Default Prompt

Here's how it looks when an administrative account is hidden.

Windows 10 UAC Hide Administrator Account

If you are running Windows 10 Pro, Enterprise, or Education edition, you can use the Local Group Policy Editor app to enable it. All editions of Windows 10 can use a Registry tweak mentioned below.

To Hide Administrator Account From UAC Prompt in Windows 10,

  1. Press Win + R keys together on your keyboard and type:

    Press Enter.Windows 10 run gpedit

  2. Group Policy Editor will open. Go to Computer Configuration\Administrative Templates\Windows Components\Credential User Interface.
  3. Double-click on the policy option Enumerate administrator accounts on elevation.Windows 10 Enumerate Administrator Accounts On Elevation
  4. Set it to Disabled.Windows 10 Enumerate Administrator Accounts On Elevation 4

If your Windows edition doesn't include the gpedit.msc tool, you can apply a Registry tweak as described below.

Hide Administrator Account from UAC Prompt with Registry Tweak

  1. Open Registry Editor.
  2. Go to the following Registry key:

    Tip: See how to jump to the desired Registry key with one click.

    If you do not have such a key, then just create it.

  3. Here, modify or create a new 32-bit DWORD value EnumerateAdministrators. Note: Even if you are running 64-bit Windows you must still create a 32-bit DWORD value. Leave its value data as 0 to enable the feature.Windows 10 Enumerate Administrator Accounts On Elevation 3
  4. A value data 1 will force disable it. By default, the value doesn't exist in the Registry.
  5. Restart Windows 10.

To save your time, you can download the following ready-to-use Registry files.

Download Registry files

The undo tweak is included.


Related articles:

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.