Microsoft has unveiled a groundbreaking security feature called Administrator Protection, now available to Windows Insiders in the Canary Channel with the release of Windows 11 Insider Preview Build 27774.
This feature, designed to strengthen system security, introduces a new approach to managing administrative privileges, addressing long-standing vulnerabilities in Windows systems.
Administrator Protection is a security enhancement aimed at mitigating risks associated with administrative accounts. Traditionally, users logged in as administrators have unrestricted access to system resources, making them prime targets for malware and attackers.
This new feature enforces the Principle of Least Privilege (PoLP) by treating administrator accounts as standard users by default. Elevated privileges are granted only on a just-in-time (JIT) basis when specific tasks require them.
Users attempting actions requiring administrative rights, such as installing software or modifying critical system settings, must authenticate explicitly when enabled.
Investigate Real-World Malicious Links & Phishing Attacks With Threat Intelligence Lookup - Try for Free
This is achieved through Windows Hello, which supports biometric authentication or PIN verification. The feature also introduces color-coded elevation prompts, which visually highlight potentially risky actions, extending these warnings over the app description for greater clarity.
“Administrator protection can now be enabled from Windows Security settings under the Account Protection tab. This allows users to enable this feature without requiring help from IT admins”, Microsoft said.
“It also allows Windows home users to enable Administrator protection via Windows Security settings”.
Currently, Administrator Protection is available exclusively to Windows Insiders running Build 27774 in the Canary Channel. Microsoft plans to refine the feature based on user feedback before rolling it out more broadly in future Windows 11 updates.
With Administrator Protection, Microsoft takes a significant step toward securing administrative accounts against privilege escalation attacks, ensuring that both home and enterprise users remain in control of their systems while minimizing risks from malicious actors.
Integrating Application Security into Your CI/CD Workflows Using Jenkins & Jira -> Free Webinar
Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…
The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…
CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…
Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…
You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…
Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…