Administrator Protection Review
ID: 1e5d664c-23fd-5456-a6c5-5a33180b6c05
STIX ID: report--1e5d664c-23fd-5456-a6c5-5a33180b6c05
Feed Name: XPN InfoSec Blog
This report analyzes Windows Administrator Protection (Shadow Admin accounts) in Windows 11, explaining the new shadow-admin model that replaces UAC split tokens, how shadow accounts are created and linked in the SAM/LSASS flows, how consent/LogonUserExExW issues tokens for admin_ accounts, and several practical bypasses and edge cases (LocalAccountTokenFilterPolicy network downgrades, RunOnce auto-elevation, UIAccess interactions) that preserve some legacy elevation behaviors and pose operational security concerns.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
