Avatar of FriendlyIT
FriendlyIT
Flag for United Kingdom of Great Britain and Northern Ireland asked on

How to work with password managers and UAC

How do I work with password managers and secure desktop?

We use a password manager but in Windows 10 because UAC prompt runs as a Secure Desktop, we can no longer paste passwords into the password field when we need to elevate privileges.

I know that there are ways to suppress this behaviour with group policy, but we are trying to work to security best practice and so that isn't ideal either.

However, these passwords are too complex for people to be typing in, so not sure how best to proceed?

Just wondering how other people are handling this kind of thing?


Jon
Windows 10Windows OSDesktopsSecurity

Avatar of undefined
Last Comment
FriendlyIT

8/22/2022 - Mon
Alex Appleton

What about using Windows Hello with a PIN?  You can also use a smart card reader, facial recognition, fingerprint, yubikey, etc..
FriendlyIT

ASKER
Thanks for the suggestions.  The problem is really relating to support tasks and things that we need to run as domain admin, so not sure any of those thoughts are particularly relevant in this scenario....
Danilo Andrade

However, these passwords are too complex for people to be typing in, so not sure how best to proceed?
The problem is really relating to support tasks and things that we need to run as domain admin
So I'm assuming the password is not for the users to be entering themselves, and more of the administrator to be typing in?

Are you remotely connecting to the computers to input the password? If so, applications like teamviewer and screenconnect (connectwise control) would allow you to paste or send clipboard keystrokes.

If you are entering the password directly on the computer, have you tried pasting it temporarily in notepad and once done just closing it without saving?
All of life is about relationships, and EE has made a viirtual community a real community. It lifts everyone's boat
William Peck
serialband

Don't create random gibberish passwords.  Make them long, but "readable" and somewhat "memorable" in some way.  I'm not sure password managers with randomly generated passwords are more secure than some long password, as long as they're not dictionary based.  It only needs to be complex enough that the password cracker can't crack your password in a "short" amount of time.  Eventually, all passwords can be cracked.  It's just a matter of time, and resources, but some passwords
McKnife

As an alternative, let me help you getting an idea when to use strong accounts and how. In my opinion, the occasions where you need to switch accounts for doing administrative things can be eliminated almost completely. I have an approach for you that does not even need a password. It is limited to local resources, though.

So let me now how you go about and why you need to switch accounts after you read my article: https://www.experts-exchange.com/articles/24599/Free-yourself-of-your-administrative-account.html
FriendlyIT

ASKER
Danilo Andrade - Yes - this is for administrators working on client machines - has historically been VNC (which haven't tested how it handles UAC prompts) also looking at Quick Assist for WIndows 10.  Pasting to Notepad I would say has additional attack vectors as then both keyloggers and screen grabs could pick it up so is probably not ideal.

serialband - Our current process is that all passwords have to be created by a password manager (we use Secret Server)

McKnife - Thanks - I will read that and digest
Get an unlimited membership to EE for less than $4 a week.
Unlimited question asking, solutions, articles and more.
ASKER CERTIFIED SOLUTION
FriendlyIT

Log in or sign up to see answer
Become an EE member today7-DAY FREE TRIAL
Members can start a 7-Day Free trial then enjoy unlimited access to the platform
Sign up - Free for 7 days
or
Learn why we charge membership fees
We get it - no one likes a content blocker. Take one extra minute and find out why we block content.
Not exactly the question you had in mind?
Sign up for an EE membership and get your own personalized solution. With an EE membership, you can ask unlimited troubleshooting, research, or opinion questions.
ask a question