A municipal Windows image shows AlwaysInstallElevated-class policy themes enabled. How should the tester classify that finding?
Select an answer to reveal the explanation.
Short Explanation
AlwaysInstallElevated is like letting every intern install software with the manager's badge. When that policy class is on, low-priv users can land elevated installer runs—a classic Windows misconfig. Call it dangerous policy, not BitLocker trivia.
Full Explanation
AlwaysInstallElevated-style policies instruct Windows Installer to run with elevated rights for both per-user and per-machine contexts when misconfigured. That creates a well-known privilege-escalation misconfiguration class on Windows workstations and servers. It is unrelated to BitLocker recovery strings or enterprise Update disablement and does not apply to Linux package managers. Report and validate within RoE rather than treating it as cosmetic.