Disable UAC in Windows 11, 10 and Server: Every Method

Logeshwaran
—

To disable UAC prompts in Windows 11 or Windows 10, press Win + R, type UserAccountControlSettings, and drag the slider to the bottom, Never notify. That stops the "Do you want to allow this app to make changes?" dialog for administrators. But here is what that slider does not do, and what almost every guide gets wrong: "Never notify" does not turn User Account Control off. UAC stays running, administrator apps are elevated silently, and standard users are still asked for an administrator password. Turning UAC fully off is a different switch, a registry value called EnableLUA or the Group Policy "Run all administrators in Admin Approval Mode," and flipping it has a cost that the slider does not: on Windows 11 and 10, Microsoft Store apps stop launching and Windows Security reports the PC as less secure. This guide covers every way to turn UAC off or down, on Home and Pro, with the registry, Group Policy, PowerShell and the command line, how to silence the prompt for one program instead of all of them, how to do it across a company, and how to turn it back on. It also tells you honestly when not to.

Jake's most-repeated request at the counter is not a repair. It is "can you make it stop asking me yes or no." He used to say yes without thinking, slide the setting to the bottom, and hand the laptop back. Then a customer came in with a laptop that had been "cleaned up" by a nephew who had gone further, disabling UAC entirely from the registry, and none of the Store apps would open, including the Photos app the customer used every day. Ethan's line, when Jake asked why the slider and the registry behaved so differently: "The slider decides whether Windows asks before it hands over the keys. The registry setting decides whether there are keys at all. Take away the keys and half the house stops working." This page is the difference between those two, written down.

⚡ Quick Answer

• Stop the prompts (any edition) → Win + R, UserAccountControlSettings, slider to Never notify, OK. No restart. What each level does.

• Same thing from the command line → reg add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System /v ConsentPromptBehaviorAdmin /t REG_DWORD /d 0 /f plus PromptOnSecureDesktop = 0. Registry values.

• Turn UAC fully off → EnableLUA = 0, then restart. Store apps stop working; Windows Security warns. Read this first.

• One program only → a Task Scheduler task with "Run with highest privileges," launched by a shortcut. Steps.

Pro, Enterprise and Education can also use secpol.msc > Local Policies > Security Options. Servers, Intune and GPO are covered in the IT section.

If you want the two-minute version: use the slider, not the registry EnableLUA switch, unless you have a specific reason and have read the section on what breaks. And if you are here because a prompt keeps appearing for one program every day, the Task Scheduler trick below removes that one prompt without lowering the wall for everything else, which is the answer most people actually want.

What UAC actually does, in two sentences

When an administrator signs in to Windows, Windows creates two access tokens: a standard-user token that runs everything by default, and a full administrator token that is used only after you approve an elevation prompt. User Account Control is the mechanism that keeps you on the standard token until a program asks for more, and asks you first. That is why malware that runs in your browser cannot silently install a driver, and why the Photos app, which is built to run in a low-privilege container, works at all. Every setting on this page is a decision about when Windows asks, whether it asks on a dimmed "secure desktop" that other programs cannot draw over, or whether the two-token model exists at all.

Two more facts help the rest make sense. The prompt is color-coded: a gray-blue header means a Windows component or an app from a verified publisher; a yellow header means the app is unsigned or its publisher is not trusted, and that yellow is the one worth a second look. And the built-in Administrator account (the hidden one, not your own admin account) does not run in Admin Approval Mode by default, so it never sees prompts; that is one reason our guide to the built-in Administrator account says to keep it disabled.

The UAC slider: what each of the four levels means

The slider is in Control Panel under User Accounts > Change User Account Control settings, and the fastest route is Win + R, UserAccountControlSettings. Each position sets two registry values, which is why the command-line methods below can do exactly what the slider does.

Slider level What happens ConsentPromptBehaviorAdmin PromptOnSecureDesktop
Always notify (top)Prompts for apps and for Windows settings changes, on the secure desktop21
Notify only when apps try to make changes (default)Prompts for non-Windows apps, on the secure desktop; Windows' own tools elevate silently51
Same, without dimming the desktopSame prompts, drawn on the normal desktop where other windows can overlap it50
Never notify (bottom)Administrators elevate without any prompt; standard users are still asked for credentials; UAC itself stays on00

The bottom position is the one people mean by "disable UAC," and for an administrator account it feels like UAC is gone: nothing ever asks. Under the hood the two-token model, the elevation, the protected-process rules and the Store app container all keep working, which is why this level is safe for apps and the registry EnableLUA switch is not. The third level, "without dimming," is the one to try if your real complaint is the screen flicker or a remote-support tool that goes black at the prompt: the dimming is the secure desktop, and turning it off keeps the prompt while fixing the flicker. Microsoft's documentation calls "elevate without prompting" a setting for "the most constrained environments," which is a polite way of saying it is your call and your risk.

Disable UAC prompts from the registry or Command Prompt (works on Home)

Everything the slider does is two DWORD values under one key, and Home editions, which lack the policy editors, can set them directly. All of these need an administrator Command Prompt or PowerShell, and they take effect without a restart for the prompt behavior.

:: Never notify (same as the slider's bottom position)
reg add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System /v ConsentPromptBehaviorAdmin /t REG_DWORD /d 0 /f
reg add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System /v PromptOnSecureDesktop /t REG_DWORD /d 0 /f

:: Back to the default (notify for non-Windows apps, secure desktop on)
reg add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System /v ConsentPromptBehaviorAdmin /t REG_DWORD /d 5 /f
reg add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System /v PromptOnSecureDesktop /t REG_DWORD /d 1 /f

The same in PowerShell, which is the form to keep in a script:

$k = "HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System"
Set-ItemProperty $k -Name ConsentPromptBehaviorAdmin -Value 0 -Type DWord
Set-ItemProperty $k -Name PromptOnSecureDesktop     -Value 0 -Type DWord

The full set of values under that key, from Microsoft's UAC settings reference, is the table below; the two above are the ones the slider moves. Note that ConsentPromptBehaviorAdmin has six meanings, and 1 and 3 (prompt for credentials) make even administrators type a password, which some households and shops use deliberately on a shared PC.

Registry value Policy name Values (default in bold)
EnableLUARun all administrators in Admin Approval Mode1 on, 0 off (the real UAC switch; restart required)
ConsentPromptBehaviorAdminBehavior of the elevation prompt for administrators0 elevate without prompting, 1 credentials on secure desktop, 2 consent on secure desktop, 3 credentials, 4 consent, 5 consent for non-Windows binaries
ConsentPromptBehaviorUserBehavior of the elevation prompt for standard users0 automatically deny, 1 credentials on secure desktop, 3 credentials
PromptOnSecureDesktopSwitch to the secure desktop when prompting1 dim, 0 do not dim
FilterAdministratorTokenAdmin Approval Mode for the built-in Administrator0 off, 1 on
EnableInstallerDetectionDetect application installations and prompt1 on Home, 0 on other editions
ValidateAdminCodeSignaturesOnly elevate executables that are signed and validated0 off, 1 on
EnableVirtualizationVirtualize file and registry write failures1 on, 0 off (old apps that write to Program Files break at 0)
EnableSecureUIAPathsOnly elevate UIAccess apps installed in secure locations1 on, 0 off

Turning UAC fully off with EnableLUA, and what breaks

This is the switch the nephew used. EnableLUA = 0 turns off Admin Approval Mode and, with it, every UAC policy: administrators run with a full token from sign-in, there is no elevation, no secure desktop, no virtualization of writes to protected folders. It needs a restart to take effect, and it is the only method on this page that Windows itself warns about.

:: Turn UAC off completely (restart required). Read the section below first.
reg add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System /v EnableLUA /t REG_DWORD /d 0 /f

:: Turn it back on (restart required)
reg add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System /v EnableLUA /t REG_DWORD /d 1 /f

What breaks, specifically, on Windows 11 and Windows 10 with UAC off:

  • Microsoft Store apps will not open. Photos, Calculator, Snipping Tool, the Store itself and any packaged app are built to run at a low integrity level that only exists when UAC is on. With EnableLUA at 0 they either refuse to launch or vanish after a second. This is the number one "my apps stopped working" cause on machines where someone "sped things up."
  • Windows Security reports reduced protection, with a persistent warning, because the policy explicitly notifies you that the overall security of the operating system is reduced.
  • File and registry virtualization ends, so old programs that quietly wrote to Program Files or HKLM and were being redirected to per-user locations now fail with access-denied errors instead.
  • Every program runs as a full administrator, including your browser and whatever it downloads. The protection that makes a browser exploit a nuisance instead of a takeover is gone.

Windows Server is the one place this switch has a defensible history, on isolated machines running an old service that cannot cope with elevation. On a desktop, in 2026, "Never notify" gives you the silence you wanted without breaking the Store, and it is the right stopping point.

Disable UAC with Group Policy or Local Security Policy (Pro, Enterprise, Education)

  1. Press Win + R, type secpol.msc, press Enter. (Or gpedit.msc and go to Computer Configuration > Windows Settings > Security Settings > Local Policies > Security Options.)
  2. Open Security Options and find the settings that begin User Account Control:.
  3. To match "Never notify": set Behavior of the elevation prompt for administrators in Admin Approval Mode to Elevate without prompting, and Switch to the secure desktop when prompting for elevation to Disabled.
  4. To turn UAC fully off: set Run all administrators in Admin Approval Mode to Disabled, then restart. Everything in the previous section applies.
  5. To make administrators type a password instead of clicking Yes, set the administrator prompt behavior to Prompt for credentials on the secure desktop.

If a setting here is grayed out, a domain Group Policy or Intune profile owns it and will overwrite anything you set locally at the next refresh. Our guide to "This setting is managed by your administrator" explains how to tell which, and if the PC is a former work machine, removing "managed by your organization" is the cleanup to do first.

Disable the UAC prompt for one specific program only

This is the answer to the question most people are really asking. A program you use every day, an old accounting package, a game launcher, a hardware utility, asks for elevation every time. You do not want to lower UAC for everything; you want that one prompt gone. Windows has no per-program UAC exception, but Task Scheduler can launch a program with highest privileges without a prompt, and a shortcut can run that task.

  1. Open Task Scheduler (search for it), and choose Create Task (not "Create Basic Task").
  2. On the General tab, give it a short name with no spaces, such as RunMyApp, and check Run with highest privileges. Leave "Run only when user is logged on" selected.
  3. On the Actions tab, add Start a program and browse to the program's .exe. Fill in "Start in" with the program's folder; many old programs need it.
  4. On the Conditions tab, clear Start the task only if the computer is on AC power, or the shortcut will silently do nothing on a laptop on battery.
  5. Create a desktop shortcut whose target is: schtasks /run /tn "RunMyApp". Give it the program's icon if you like.

Double-clicking the shortcut runs the task, which runs the program elevated, with no prompt, while every other program on the PC keeps its normal protection. Two limits: the task runs the program as you, so you must be an administrator (that is what "highest privileges" elevates to), and the program starts a second or two slower because it goes through the scheduler. For a standard-user account there is no silent path by design; the answer there is to give the user the rights the program needs, for example on a folder, rather than administrator rights on the PC.

UAC for standard users: the prompt you cannot click through

Everything above assumes you sign in as an administrator. On a standard account the prompt looks different and behaves differently: instead of Yes and No, it asks for an administrator's user name and password, and the slider has no effect on it at all. That is by design. A standard user has no administrator token to unlock, so "elevate without prompting" has nothing to elevate. The controlling setting is Behavior of the elevation prompt for standard users (ConsentPromptBehaviorUser): 3, the default, prompts for credentials; 1 prompts on the secure desktop; 0 denies automatically with a plain access-denied message, which companies use so that a locked-down desktop fails cleanly instead of nagging.

For a family PC, this is the arrangement worth keeping rather than fighting: the kids and the daily account run as standard users, one administrator account exists for installs, and the credential prompt is the moment an adult decides. If a standard user needs to run one program that demands elevation every day, the fix is to give that program's folder or registry key the permissions it wants, or to install a version that does not require administrator rights, not to hand out the administrator password. Our guide on local and Microsoft accounts explains how to check which kind of account each person has.

Check the current UAC state with PowerShell or the command line

Before you change anything on someone else's machine, read what is there. One line shows the key values:

Get-ItemProperty "HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System" |
  Select-Object EnableLUA, ConsentPromptBehaviorAdmin, ConsentPromptBehaviorUser, PromptOnSecureDesktop

Read it against the tables above: 1 / 5 / 3 / 1 is the untouched default; 1 / 0 / 3 / 0 is "Never notify"; anything with EnableLUA at 0 is fully off and explains missing Store apps. From a plain Command Prompt, reg query HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System /v EnableLUA answers the one question that matters most.

The 2026 change: Administrator protection

UAC is not standing still. Windows 11 is rolling out a replacement for the "click Yes" model called Administrator protection. Instead of giving your account a full administrator token that a prompt unlocks, Windows keeps you as a standard user all the time and, when something needs elevation, creates a separate, hidden, system-managed administrator identity just for that operation, asks you to approve it with Windows Hello (face, fingerprint or PIN), and discards the elevated context when the task ends. The point is that malware can no longer ride on a token that is already sitting in your session waiting for a Yes. It is off by default, and Microsoft began rolling it out through the optional preview update KB5124006 for Windows 11 version 26H1 on September 22, 2026, with enablement through Intune or Group Policy. If your organization turns it on, the "Never notify" slider stops being the relevant control, because there is no standing administrator token to elevate silently. For home users nothing changes yet; for IT, it is the direction to plan toward rather than lowering UAC.

For IT admins: UAC on servers, by GPO and by Intune

The most-searched version of this question is "disable UAC on Windows Server," and it needs a precise answer because the slider is not the tool there.

  • Windows Server 2016, 2019, 2022 and 2025 use the same policies and registry values as the client. The slider exists but is the wrong instrument for a fleet; set the User Account Control: policies under Computer Configuration > Windows Settings > Security Settings > Local Policies > Security Options in a GPO linked to the server OU.
  • "Disable UAC" on a server usually means one of two things. An application vendor asked for it, in which case first try Elevate without prompting plus secure desktop off, which quiets prompts for scheduled and service contexts without disabling Admin Approval Mode. Or an old service genuinely needs UAC gone, in which case Run all administrators in Admin Approval Mode: Disabled, a restart, and a note in the change record that Windows Security will flag the host and packaged apps will not run (on Server, that is usually the Windows Admin Center and Store-based tools).
  • Remote administration from local accounts is governed by a different setting: UAC remote restrictions filter the token of local administrator accounts over the network on workgroup machines, so \\server\c$ and remote shutdown fail with access denied even with a correct password. The switch is LocalAccountTokenFilterPolicy = 1 under the same Policies\System key; domain accounts are not affected. Do not confuse that with disabling UAC.
  • Intune: the same ten settings live in the settings catalog under Local Policies Security Options, and in the LocalPoliciesSecurityOptions CSP as UserAccountControl_* values; for example UserAccountControl_BehaviorOfTheElevationPromptForAdministrators and UserAccountControl_RunAllAdministratorsInAdminApprovalMode. A device receiving conflicting values from GPO and Intune is the usual cause of a setting that will not stay put.
  • Standard-user desktops: set Behavior of the elevation prompt for standard users to Automatically deny elevation requests; users get a clean access-denied message instead of a credential prompt they cannot satisfy, which cuts help-desk calls, and pair it with an application-deployment tool such as Intune so they never need to elevate.
  • Baselines: Microsoft's security baselines keep Admin Approval Mode enabled, administrators at "Prompt for consent on the secure desktop," and the built-in Administrator in Admin Approval Mode. Deviations are exceptions to document, and Administrator protection is the 2026 destination.

How do I disable UAC in Windows 11?

Press Win+R, type UserAccountControlSettings, press Enter, drag the slider to Never notify and choose OK. This stops elevation prompts for administrators immediately, without a restart, while leaving User Account Control itself running. To turn UAC off entirely, set the registry value EnableLUA to 0 under HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System and restart, which also stops Microsoft Store apps from launching.

How do I disable UAC in Windows 10?

The same way as Windows 11: Win+R, UserAccountControlSettings, slider to Never notify. The registry values, Group Policy settings and the EnableLUA switch are identical on Windows 10, with the same effect on Store apps when UAC is fully disabled.

What is the difference between Never notify and disabling UAC?

Never notify sets ConsentPromptBehaviorAdmin to 0 and PromptOnSecureDesktop to 0: administrators elevate silently, but Admin Approval Mode, the two-token model, virtualization and the app container all keep working, and standard users still get credential prompts. Disabling UAC sets EnableLUA to 0, which removes Admin Approval Mode entirely, breaks Microsoft Store apps and makes Windows Security warn that security is reduced.

Why do Store apps not open after disabling UAC?

Packaged apps such as Photos, Calculator and the Store run at a low integrity level that exists only when User Account Control is enabled. With EnableLUA set to 0, that level is unavailable and the apps fail to launch. Set EnableLUA back to 1 and restart.

How do I disable UAC with the registry on Windows 11 Home?

In an administrator Command Prompt, run reg add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System /v ConsentPromptBehaviorAdmin /t REG_DWORD /d 0 /f and the same for PromptOnSecureDesktop with /d 0. That matches Never notify with no restart. Home lacks the policy editors, so the registry is the direct route.

How do I disable UAC with Group Policy?

Open secpol.msc or gpedit.msc, go to Local Policies, Security Options, and set User Account Control: Behavior of the elevation prompt for administrators to Elevate without prompting and Switch to the secure desktop to Disabled. To turn UAC fully off, set Run all administrators in Admin Approval Mode to Disabled and restart.

How do I disable UAC with PowerShell or CMD?

PowerShell: Set-ItemProperty on HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System for ConsentPromptBehaviorAdmin (0) and PromptOnSecureDesktop (0), run as administrator. CMD: the equivalent reg add commands. Both match the Never notify slider and take effect without a restart.

Can I disable UAC for a specific program only?

Not with a UAC setting; there is no per-program exception. The working method is a Task Scheduler task with Run with highest privileges that starts the program, launched by a shortcut whose target is schtasks /run /tn "TaskName". That program then starts elevated without a prompt while UAC stays on for everything else.

How do I disable UAC on Windows Server?

Use Group Policy rather than the slider: under Local Policies, Security Options, set the administrator elevation prompt to Elevate without prompting and secure desktop to Disabled to quiet prompts, or set Run all administrators in Admin Approval Mode to Disabled and restart to turn UAC off entirely. The same applies to Windows Server 2016, 2019, 2022 and 2025. Remote access-denied errors for local accounts are a separate setting, LocalAccountTokenFilterPolicy.

Does disabling UAC require a restart?

Changing the prompt behavior, whether by slider, registry or policy, takes effect immediately. Changing EnableLUA, which turns Admin Approval Mode on or off, requires a restart.

How do I turn UAC back on?

Move the slider back to the default second position, or set ConsentPromptBehaviorAdmin to 5 and PromptOnSecureDesktop to 1. If UAC was fully disabled, set EnableLUA to 1 and restart. Windows Security stops warning once Admin Approval Mode is back on.

Is it safe to disable UAC?

Never notify is a reasonable trade on a single-user PC where you understand that any program you run gets administrator rights without asking. Turning UAC fully off with EnableLUA is not recommended on any desktop: it breaks Store apps, removes the protection that keeps browser exploits contained, and disables file and registry virtualization for older programs.

How do I stop the screen from dimming at the UAC prompt?

Choose the third slider position, "Notify me only when apps try to make changes (do not dim my desktop)," or set PromptOnSecureDesktop to 0. The prompt remains but appears on the normal desktop, which fixes flicker and black screens in some remote-support tools, at the cost of letting other windows draw over the prompt.

How do I make UAC ask for a password instead of Yes and No?

Set Behavior of the elevation prompt for administrators in Admin Approval Mode to Prompt for credentials on the secure desktop, or set ConsentPromptBehaviorAdmin to 1. Administrators then type their password at every elevation, which some shared PCs use deliberately.

What is Administrator protection in Windows 11?

A newer model that keeps every user as a standard user and creates a temporary, system-managed administrator identity only for the duration of an elevated operation, approved through Windows Hello. It began rolling out as an off-by-default option in the September 22, 2026 preview update for Windows 11 version 26H1, enabled through Intune or Group Policy, and is intended to replace the standing administrator token that UAC prompts unlock.

Why does UAC keep turning itself back on?

A domain Group Policy, an Intune profile or a security baseline is enforcing it and reapplies at every policy refresh. On a managed PC, change it in the management tool; on a former work PC, remove the leftover management first.

Jake's counter rule is now two sentences he says out loud before touching the setting: "The slider makes it stop asking. The registry makes it stop working." Most people who want UAC gone want the first, and the slider gives it to them in ten seconds with nothing broken. The few who genuinely need the second, usually on a server, should know what stops working before they restart. And if the prompt is only ever for one program, the scheduled task is the fix that lowers nothing at all.

📌 If you keep one line from this page

"Never notify" silences UAC; EnableLUA = 0 removes it, and takes your Store apps with it.

Use the slider for silence, a scheduled task for one program, and Group Policy or Intune for a fleet.

Revision note. This guide was first published in May 2016 and lightly updated since. It was rewritten on September 29, 2026 for Windows 11, Windows 10 and Windows Server from Microsoft's User Account Control settings and configuration references, adding the slider-to-registry mapping, the difference between silencing and disabling UAC, the per-program scheduled-task method, the Administrator protection rollout of September 22, 2026, and an IT admin section covering servers, GPO and Intune.

Related