Access Keys:
Skip to content (Access Key - 0)

Q: Enabling User Account Control

  • Domain joined computers running Windows 8.1 and Windows 10 may receive the error “This app can’t open for Built-in Administrator account” when trying to run Universal “Modern” Apps such as Edge Browser, Calculator, Microsoft Store, Weather App, etc.:
    This app can't open

Context

  • This issue is occurring because these apps require User Account Control (UAC) to be enabled due to Application Sandboxing.  By default UAC is disabled at the root level of the WIN domain due to current compatibility issues with MIT Kerberos for Windows.
  • This fix is applied via a group policy object and must be performed by an IT technician with the appropriate permissions to the GPO.
  • Important! If you are using SAP you will need to apply an environmental variable change first. Once this change is in place the UAC can be enabled in the case where MIT’s Kerberos for Windows was only used for access to SAP.

Answer

  1. Access the related Organization Unit GPO through Group Policy Management Console.  This is done through Citrix under the WIN Container Admin Toolshttps://citrixapps.mit.edu/Citrix/XenApp/auth/login.aspx
  1. Once you locate your related GPO right click and select edit
  2. Navigate to Computer Configuration/Policies/Windows Settings/Security Settings/Local Policies/Security Options/
  3. Set the parameter User Account Control: Run all administrators in Admin Approval Mode to Enabled.
    Group Policy Management Editor tree
    Enable User Account Control
  4. Please Note:  This change will enable UAC for all computers in the OU including Windows 7 computers.  Users will experience additional approval prompts with UAC enabled.
  5. A reboot will be required after the policy is applied (either with a gpupdate /force or wait 120 minutes).

See Also

IS&T Contributions

Documentation and information provided by IS&T staff members


Last Modified:

November 20, 2020

Get Help

Request help
from the Help Desk
Report a security incident
to the Security Team
Labels:
c-win-mit-edu c-win-mit-edu Delete
uac uac Delete
user user Delete
account account Delete
control control Delete
windows windows Delete
group group Delete
policy policy Delete
kerberos kerberos Delete
Enter labels to add to this page:
Please wait 
Looking for a label? Just start typing.
Feedback
This product/service is:
Easy to use
Average
Difficult to use

This article is:
Helpful
Inaccurate
Obsolete
Adaptavist Theme Builder (4.2.3) Powered by Atlassian Confluence 3.5.13, the Enterprise Wiki