A user reported an unusual problem: when attempting to run any program as an administrator in Windows 11, the User Account Control (UAC) prompt appears and requests elevation, but the Yes button is missing or grayed out. The only available option is No. Moreover, the UAC window prompts you to enter administrator credentials, but there are no fields where those credentials can be entered.
The screenshot below shows an example of what such a strange UAC prompt looks like:
Do you want to allow this app to make changes to your device To continue, enter an admin username and password.
This UAC prompt behavior indicates that there are no admin accounts on the computer that can be used to approve the elevation request. This means that the account currently signed in to Windows also doesn’t have administrator privileges and has become a regular unprivileged user account.
Even if the account previously had administrator privileges, the user may have been removed from the built-in Administrators group for some reason, either accidentally or intentionally.
Open a non-elevated command prompt and find the name of the user who is currently signed in:
whoami
In this example, the username is winos. Сheck the account type using the following PowerShell command:
Get-LocalUser winos | FL
In this example, the PrincipalSource value shows that the computer used with a Microsoft Account (MSA) rather than a local Windows 11 account.
Now check the list of groups that the user is a member of:
net user winos
In this case, the user is only a member of the local Users group (Local Group Memberships: * Users). The local Administrators group is not listed in its memberships.
In order to add the user to the local Administrators group, restart the computer in the Windows Recovery Environment (WinRE). To do this, hold down the Shift key and click Restart in the Start menu, or run the following command:
shutdown /r /o /t 0
After rebooting into the Windows Recovery Environment, navigate to Troubleshoot -> Advanced Options -> Command Prompt.
The Windows Recovery Environment (WinRE) has a relatively little-known feature. If User Account Control (UAC) is enabled on the computer and there are no active (enabled) administrator accounts in the operating system, WinRE automatically signs in using the built-in Administrator account. This account is automatically enabled in this scenario, and no password is required to sign in.
All you need to do is add the user account whose name you found out earlier to the local Administrators group. Use this command (replace the account name with your own):
net localgroup Administrators winos /add
Restart your computer and check if UAC is now working properly.
However, if you use a Microsoft account to sign in to Windows, as in our example, you cannot add it to the local Administrators group from WinRE. The Windows Recovery Environment does not recognize Microsoft accounts.
In this case, proceed as follows:
- Enable the built-in administrator account and set its password:
net user Administrator /active:yes
net user Administrator * - Close the command prompt in WinRE and restart the computer in Safe Mode (Troubleshoot -> Advanced options -> Startup Settings -> Restart -> press
F4). Select the Administrator account from the list of users on the Windows sign-in screen. - Sign in with the Administrator account, open an elevated Command Prompt (by selecting Run as administrator), and add your Microsoft account to the local Administrators group:
net localgroup Administrators winos /add
- Restart Windows and then sign in using your Microsoft account.
- Check that the UAC prompt now displays the ‘Yes’ button. Once everything is working correctly, make sure to disable the built-in Administrator account:
net user Administrator /active:no






