Requirements on User Account Control (UAC)

On a machine that is running Windows Vista or later and is not a member of an Active Directory domain, centralized management operations (including remote installation) require that UAC and UAC remote restrictions be disabled.

To disable UAC

Do one of the following depending on the operating system:

  • In a Windows operating system prior to Windows 8:

    Go to Control panel  > View by: Small icons  > User Accounts > Change User Account Control Settings, and then move the slider to Never notify. Then, restart the machine.

  • In any Windows operating system:

    1. Open Registry Editor.
    2. Locate the following registry key: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System
    3. For the EnableLUA value, change the setting to 0.
    4. Restart the machine.

To disable UAC remote restrictions

  1. Open Registry Editor.
  2. Locate the following registry key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System
  3. For LocalAccountTokenFilterPolicy value, change the setting to 1.

    If the LocalAccountTokenFilterPolicy value does not exist, create it as DWORD (32-bit). For more information about this value, refer to the Microsoft documentation: https://support.microsoft.com/en-us/help/951016/description-of-user-account-control-and-remote-restrictions-in-windows.

For security reasons, it is recommended that after finishing the management operation – for example, remote installation, both of the settings be reverted to their original state: EnableLUA=1 and LocalAccountTokenFilterPolicy = 0