How to remove UAC shield icon from shortcuts when UAC is disabled?


Recommended Posts

  On 25/09/2023 at 17:15, grunger106 said:

The point people are trying to make is yes you CAN disable UAC but (even if you 'know what you're doing') you shouldn't.

Maybe the question should be, other than to prove you can, what do think you gain by doing so?

As @satukoro has said, you can auto-elevate a program in Windows, but this requires storing credentials in a potentially reversable format, again not a good idea (although I think their comment was more for example than a suggestion of something you do)

Auto-elevation is a bad thing, stored credentials are a bad thing, can you - sure, should you, no - there are a million things you *can* do, I can install Windows XP, put a hacked up 'SP4' on it and bring put it on the internet, will it load pages and run software? Sure, is it a good idea? no.
 

Expand  

I would not say that is a good idea unless you know what you are doing.

I also do not endorse to do such things on work environments.

If anything this is only for personal use, and BTW, I do have both Win98 and WinXP retro machines with as many updates as possible (not breaking compatibility) for some older games I play. So in a sense I do the stuff you think it is not a good idea, but these are not my main machines nor I do anything relevant in them other than turning them on once in a while purely by nostalgic reasons.

 

  On 25/09/2023 at 18:15, Arceles said:

I would not say that is a good idea unless you know what you are doing.

I also do not endorse to do such things on work environments.

If anything this is only for personal use, and BTW, I do have both Win98 and WinXP retro machines with as many updates as possible (not breaking compatibility) for some older games I play. So in a sense I do the stuff you think it is not a good idea, but these are not my main machines nor I do anything relevant in them other than turning them on once in a while purely by nostalgic reasons.

 

Expand  

As do I, I have an XP box, a 98 box and a pair Dos 6.22 VMs, however they are all isolated from the world and other machines (or are on a VLAN that is for that DOS 6.22 Doom deathmatch goodness).

I've got 2 MAME cabs with all sorts of scripting, AV fully disabled, again air-gapped, single purpose boxes (still have UAC ;), not that it really matters)
But those are non-connected, non-standard specific case machines - If the box is air-gapped, then go nuts. If the box isn't, leave it default.


The term 'know what your doing' is on that strikes fear into sysadmins TBH.

Generally in my career I've seen 3 groups of users.
1. Don't know what they're doing, and leave stuff alone
2. Really know what they're doing and leave stuff alone (OR make well informed changes via supported paths - via GP, MDM, SCCM etc or using DSC, Terraform etc)
3. Think they know what they're doing, and tweak stuff, customise stuff, break stuff and then blame the vendor - AKA know enough to cause trouble,
 

  • Like 2
  On 25/09/2023 at 18:27, grunger106 said:

As do I, I have an XP box, a 98 box and a pair Dos 6.22 VMs, however they are all isolated from the world and other machines (or are on a VLAN that is for that DOS 6.22 Doom deathmatch goodness).

I've got 2 MAME cabs with all sorts of scripting, AV fully disabled, again air-gapped, single purpose boxes (still have UAC ;), not that it really matters)
But those are non-connected, non-standard specific case machines - If the box is air-gapped, then go nuts. If the box isn't, leave it default.


The term 'know what your doing' is on that strikes fear into sysadmins TBH.

Generally in my career I've seen 3 groups of users.
1. Don't know what they're doing, and leave stuff alone
2. Really know what they're doing and leave stuff alone (OR make well informed changes via supported paths - via GP, MDM, SCCM etc or using DSC, Terraform etc)
3. Think they know what they're doing, and tweak stuff, customise stuff, break stuff and then blame the vendor - AKA know enough to cause trouble,
 

Expand  

Yeah well, you are talking pretty much in work environments, in  such case the computer pretty much belongs to the company and you are not allowed to do anything in them... usually. If not, this is a potential security risk no matter how informed is the person and these machines should still be handled by the manual.

I would not go as to air gap win 98 and win xp machines, I see no need for it you can be so much paranoic about some stuff. Then again I use them at best 1 or 2 hours and browsing websites is not exactly feasible due to their slowness, LAN is used there just to transfer files and UAC there is disabled as I thinker with them a lot.  I would go as far as to air gap them if they were constantly on but they aren't.

My current windows 10 install in the rog ally is also with UAC disabled. I do not use anything there outside of steam and emulators and I know very well the risk of having UAC off but then again I did this with all of my personal windows installs since windows vista and not a single issue. Sue me if you want but I had no real issues with that.

  On 25/09/2023 at 17:23, adrynalyne said:

If people are having issues with the workflow of running things as admin and UAC, there is a “sudo” package for Windows that will prompt UAC automatically and allow to elevate permissions. 
 

https://github.com/gerardog/gsudo
 

 

Expand  

Doesn't winget/wingetui use gsudo?

  On 25/09/2023 at 19:55, Matthew S. said:

Doesn't winget/wingetui use gsudo?

Expand  

The more I think about it, I don't think so. appx apps install local to the account and msi installers handle UAC.

I think the installers are what prompt UAC in those cases.

if I get a chance I'll check tonight and see if I have pending updates for .exe installers, pretty sure I've seen gsudo flash before.

  On 26/09/2023 at 02:37, Matthew S. said:

Yup uses gsudo

image.png.b97fafe8a83955668c416a8925a651fb.png

Expand  

Is it just the third party front end using it? I’ve always just used CLI. It’s handy. I install it along with nvm for Windows on any machine I use and consider them staples. 

  On 24/09/2023 at 14:14, Arceles said:

Cool, the only fallacy I see here is how a bunch of people that believe themselves security experts think that everything should be one way, the windows way and I seriously disagree with it.

Expand  

The one pretending to be an expert here is you.

 

I'm actually a retired Microsoft employee that's a subject matter expert in social engineering and cybersecurity. 

 

You can continue to disagree with reality all you want. No one is stopping you.

  On 27/09/2023 at 00:42, DewThePDX said:

The one pretending to be an expert here is you.

 

I'm actually a retired Microsoft employee that's a subject matter expert in social engineering and cybersecurity. 

 

You can continue to disagree with reality all you want. No one is stopping you.

Expand  

I hope you also haven't forgotten to read all the previous post. Btw, being an ex Microsoft employee does not sound nice, never has.

  On 27/09/2023 at 05:34, Arceles said:

I hope you also haven't forgotten to read all the previous post. Btw, being an ex Microsoft employee does not sound nice, never has.

Expand  

Wow, class act you are.  He's retired, meaning he left the company on his own terms.

  On 27/09/2023 at 05:34, Arceles said:

I hope you also haven't forgotten to read all the previous post. Btw, being an ex Microsoft employee does not sound nice, never has.

Expand  

I work with Microsoft employees regularly (weekly), they seem to enjoy their job... No, not break fix (tech support).

I don't mind when they cover the bill on a Friday arvo.

  On 27/09/2023 at 05:58, Matthew S. said:

Wow, class act you are.  He's retired, meaning he left the company on his own terms.

Expand  

Is not the retirement part (which, good for him), is the microsoft part that never has sounded any bit good. I also have been offered some positions there, but I have seen the entire story of MS so far and I do not like them one bit as an enterprise, their OSes were good until windows 10 though.

  On 27/09/2023 at 13:36, Arceles said:

Is not the retirement part (which, good for him), is the microsoft part that never has sounded any bit good. I also have been offered some positions there, but I have seen the entire story of MS so far and I do not like them one bit as an enterprise, their OSes were good until windows 10 though.

Expand  

Understood.

 

You're worth no further consideration.

Man this thread is weird. I'm lost but are some people here really arguing that disabling UAC is a good thing and wont impact the security of your OS? Because man that's a weird argument to make. I mean you want to disable UAC and remove the icon fine that's your call but i don't think Neowin is the place to ask how to do that. Obviously mostly everyone here will recommend you to keep it on as it should be.

I think you can make a scheduled task and run it from a link if you want to avoid the UAC prompt for a particular program.

Edited by LaP
  • Like 2
  On 27/09/2023 at 19:03, DewThePDX said:

Understood.

 

You're worth no further consideration.

Expand  

Glad you reached that conclusion, I can follow your example and do exactly the same.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.