Windows 11 starts receiving “Administrator protection”

Windows 11 has begun gradually receiving “Administrator protection” (Administrator protection) — a mechanism that stops programs from quietly gaining admin rights. The feature is listed among the changes in Release Preview build 28000.3079 (KB5124006) dated September 11, 2026: the build belongs to Windows 11 version 26H1, and the description explicitly states that a gradual rollout is beginning.
The idea is that administrative tasks run with temporary privileges — only when needed, rather than permanently. To achieve this, the system isolates the profile: an application does not run with the full set of rights all the time, but receives them for a specific action. This separation is meant to make privilege-escalation attacks harder.
The mechanism is not new: it was reported back in October 2025 (KB5067036), and now its gradual rollout has started. The feature is off by default — it has to be enabled via OMA-URI in Microsoft Intune or through group policies. So it is too early to talk about mass enablement: without configuration on the IT side, the mechanism will not work.
Microsoft separately notes: Administrator protection is not classified as a formal security boundary. It is an additional barrier against privilege-escalation attacks through profile separation, not a replacement for other protections.
For the ordinary user the point is simple: malicious software has a harder time quietly seizing admin rights — provided the feature is enabled.
Image: OS: Microsoft Corporation
Screenshot: PantheraLeo1359531 😺 ( talk ) Public domain
Primary source: learn.microsoft.com ↗