We help IT Professionals succeed at work.

How to work with password managers and UAC

186 Views
Last Modified: 2019-02-13
How do I work with password managers and secure desktop?

We use a password manager but in Windows 10 because UAC prompt runs as a Secure Desktop, we can no longer paste passwords into the password field when we need to elevate privileges.

I know that there are ways to suppress this behaviour with group policy, but we are trying to work to security best practice and so that isn't ideal either.

However, these passwords are too complex for people to be typing in, so not sure how best to proceed?

Just wondering how other people are handling this kind of thing?


Jon
Comment
Watch Question

Alex AppletonBusiness Technology Analyst
CERTIFIED EXPERT

Commented:
What about using Windows Hello with a PIN?  You can also use a smart card reader, facial recognition, fingerprint, yubikey, etc..
FriendlyITInfrastructure Team

Author

Commented:
Thanks for the suggestions.  The problem is really relating to support tasks and things that we need to run as domain admin, so not sure any of those thoughts are particularly relevant in this scenario....
Danilo AndradeIT Systems Analyst

Commented:
However, these passwords are too complex for people to be typing in, so not sure how best to proceed?
The problem is really relating to support tasks and things that we need to run as domain admin
So I'm assuming the password is not for the users to be entering themselves, and more of the administrator to be typing in?

Are you remotely connecting to the computers to input the password? If so, applications like teamviewer and screenconnect (connectwise control) would allow you to paste or send clipboard keystrokes.

If you are entering the password directly on the computer, have you tried pasting it temporarily in notepad and once done just closing it without saving?
CERTIFIED EXPERT

Commented:
Don't create random gibberish passwords.  Make them long, but "readable" and somewhat "memorable" in some way.  I'm not sure password managers with randomly generated passwords are more secure than some long password, as long as they're not dictionary based.  It only needs to be complex enough that the password cracker can't crack your password in a "short" amount of time.  Eventually, all passwords can be cracked.  It's just a matter of time, and resources, but some passwords
CERTIFIED EXPERT
Distinguished Expert 2019

Commented:
As an alternative, let me help you getting an idea when to use strong accounts and how. In my opinion, the occasions where you need to switch accounts for doing administrative things can be eliminated almost completely. I have an approach for you that does not even need a password. It is limited to local resources, though.

So let me now how you go about and why you need to switch accounts after you read my article: https://www.experts-exchange.com/articles/24599/Free-yourself-of-your-administrative-account.html
FriendlyITInfrastructure Team

Author

Commented:
Danilo Andrade - Yes - this is for administrators working on client machines - has historically been VNC (which haven't tested how it handles UAC prompts) also looking at Quick Assist for WIndows 10.  Pasting to Notepad I would say has additional attack vectors as then both keyloggers and screen grabs could pick it up so is probably not ideal.

serialband - Our current process is that all passwords have to be created by a password manager (we use Secret Server)

McKnife - Thanks - I will read that and digest
Infrastructure Team
Commented:
This one is on us!
(Get your first solution completely free - no credit card required)
UNLOCK SOLUTION
Unlock the solution to this question.
Join our community and discover your potential

Experts Exchange is the only place where you can interact directly with leading experts in the technology field. Become a member today and access the collective knowledge of thousands of technology experts.

*This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

OR

Please enter a first name

Please enter a last name

8+ characters (letters, numbers, and a symbol)

By clicking, you agree to the Terms of Use and Privacy Policy.