logo

Administrator Protection Review

ID: 1e5d664c-23fd-5456-a6c5-5a33180b6c05

STIX ID: report--1e5d664c-23fd-5456-a6c5-5a33180b6c05

Feed Name: XPN InfoSec Blog

Threat Score
45/100

Date Published: 2025-06-20

Date Updated: 2026-07-27

...
...

This report analyzes Windows Administrator Protection (Shadow Admin accounts) in Windows 11, explaining the new shadow-admin model that replaces UAC split tokens, how shadow accounts are created and linked in the SAM/LSASS flows, how consent/LogonUserExExW issues tokens for admin_ accounts, and several practical bypasses and edge cases (LocalAccountTokenFilterPolicy network downgrades, RunOnce auto-elevation, UIAccess interactions) that preserve some legacy elevation behaviors and pose operational security concerns.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.