How to work with password managers and UAC

FriendlyIT
FriendlyIT used Ask the Experts™
on
How do I work with password managers and secure desktop?

We use a password manager but in Windows 10 because UAC prompt runs as a Secure Desktop, we can no longer paste passwords into the password field when we need to elevate privileges.

I know that there are ways to suppress this behaviour with group policy, but we are trying to work to security best practice and so that isn't ideal either.

However, these passwords are too complex for people to be typing in, so not sure how best to proceed?

Just wondering how other people are handling this kind of thing?


Jon
Comment
Watch Question

Do more with

Expert Office
EXPERT OFFICE® is a registered trademark of EXPERTS EXCHANGE®
Alex AppletonBusiness Technology Analyst

Commented:
What about using Windows Hello with a PIN?  You can also use a smart card reader, facial recognition, fingerprint, yubikey, etc..
FriendlyITInfrastructure Team

Author

Commented:
Thanks for the suggestions.  The problem is really relating to support tasks and things that we need to run as domain admin, so not sure any of those thoughts are particularly relevant in this scenario....
Danilo AndradeIT Systems Analyst

Commented:
However, these passwords are too complex for people to be typing in, so not sure how best to proceed?
The problem is really relating to support tasks and things that we need to run as domain admin
So I'm assuming the password is not for the users to be entering themselves, and more of the administrator to be typing in?

Are you remotely connecting to the computers to input the password? If so, applications like teamviewer and screenconnect (connectwise control) would allow you to paste or send clipboard keystrokes.

If you are entering the password directly on the computer, have you tried pasting it temporarily in notepad and once done just closing it without saving?
Ensure you’re charging the right price for your IT

Do you wonder if your IT business is truly profitable or if you should raise your prices? Learn how to calculate your overhead burden using our free interactive tool and use it to determine the right price for your IT services. Start calculating Now!

Don't create random gibberish passwords.  Make them long, but "readable" and somewhat "memorable" in some way.  I'm not sure password managers with randomly generated passwords are more secure than some long password, as long as they're not dictionary based.  It only needs to be complex enough that the password cracker can't crack your password in a "short" amount of time.  Eventually, all passwords can be cracked.  It's just a matter of time, and resources, but some passwords
Distinguished Expert 2018

Commented:
As an alternative, let me help you getting an idea when to use strong accounts and how. In my opinion, the occasions where you need to switch accounts for doing administrative things can be eliminated almost completely. I have an approach for you that does not even need a password. It is limited to local resources, though.

So let me now how you go about and why you need to switch accounts after you read my article: https://www.experts-exchange.com/articles/24599/Free-yourself-of-your-administrative-account.html
FriendlyITInfrastructure Team

Author

Commented:
Danilo Andrade - Yes - this is for administrators working on client machines - has historically been VNC (which haven't tested how it handles UAC prompts) also looking at Quick Assist for WIndows 10.  Pasting to Notepad I would say has additional attack vectors as then both keyloggers and screen grabs could pick it up so is probably not ideal.

serialband - Our current process is that all passwords have to be created by a password manager (we use Secret Server)

McKnife - Thanks - I will read that and digest
Infrastructure Team
Commented:
We are using VNC which allows you to paste into UAC boxes

Do more with

Expert Office
Submit tech questions to Ask the Experts™ at any time to receive solutions, advice, and new ideas from leading industry professionals.

Start 7-Day Free Trial