Cyber Cloud Ops Logo
Microsoft Intune

Enforce Consistent Security: Control the Account Protection UI in Windows Security via Intune

By Admin User
January 19, 2026
13 min
Enforce Consistent Security: Control the Account Protection UI in Windows Security via Intune

When it comes to endpoint security, visibility matters but control matters even more. In many environments, exposing security areas that users are not meant to manage can lead to confusion, unnecessary questions, and even risk.

The Account Protection area in Windows Security is one of those sections. While it provides valuable information, it also exposes account-related security features that are typically centrally enforced through Intune and should not be modified by end users.

With Intune, administrators can precisely control whether the Account Protection area is visible in the Windows Security app. This allows IT teams to define the right balance between transparency and governance, ensuring users see only what they are expected to interact with.

By hiding the Account Protection section, organizations maintain a consistent and protected security experience across managed devices. Sensitive account settings remain enforced by policy, untouched by user actions, and aligned with corporate security standards.

At the same time, this approach improves the overall user experience. A cleaner Windows Security interface reduces confusion, sets clear boundaries around security responsibilities, and helps minimize unnecessary help desk tickets related to settings users are not authorized to change.

Why This Policy Matters

In managed and security-focused environments, consistency and control are critical. Allowing end users to view or interact with sensitive account-related security settings can introduce unnecessary risk, confusion, and support overhead.

This policy ensures that security decisions remain centralized with IT, not delegated to end users. By controlling the visibility of the Account Protection area, organizations reduce the likelihood of users questioning, attempting to override, or misinterpreting security configurations that are already enforced through Intune.

From an operational perspective, this leads to:

  • A consistent security posture across all managed devices

  • Reduced risk of accidental changes or misconfiguration

  • Fewer help desk tickets related to restricted security settings

  • Clear ownership of security controls by IT and security teams

Ultimately, this policy helps organizations move closer to a standardized, predictable, and governed endpoint security model.

Why Hiding the Account Protection UI Improves Security Governance

Hiding the Account Protection UI is not about limiting transparency it’s about enforcing governance.

In modern endpoint management, users are not expected to manage or modify security controls such as credential protection, account hardening, or identity-related safeguards. These settings should be defined, enforced, and monitored centrally using tools like Intune and Microsoft Defender.

By removing the Account Protection section from Windows Security:

  • Users can no longer view or attempt to interact with protected account settings

  • There is no ambiguity about who controls security decisions

  • The risk of users searching for workarounds or exceptions is significantly reduced

At the same time, this approach improves the end-user experience. A simplified Windows Security interface removes options that users are not authorized to change, reducing confusion and increasing trust in the organization’s security model.

This aligns directly with Zero Trust principles, where security is enforced by design, continuously validated, and never dependent on user behavior.

Windows CSP Details

This policy is applied at the device level, not the user level, meaning it affects the entire device regardless of which user signs in. This ensures consistent enforcement across all managed endpoints.

It supports the following Windows editions:

  • Windows 10 Pro

  • Enterprise

  • Education

  • IoT Enterprise / IoT Enterprise LTSC

The policy is supported on Windows 10 version 1803 (build 10.0.17134) and later, which guarantees broad compatibility across modern Windows 10 and Windows 11 devices managed with Intune.

Enforce Consistent Security: Control the Account Protection UI in Windows Security via Intune - Fig. 01

By leveraging this CSP, administrators can centrally control whether the Account Protection area is visible in the Windows Security app, preventing users from accessing or interacting with account-related security settings that are already enforced by Intune.

Policy Properties

The configuration framework for this policy defines the following properties:

  • Format: Integer (int)

  • Access Type: Add, Delete, Get, Replace

  • Default Value: 0

This structure ensures the policy can be consistently deployed, updated, or replaced across managed devices using Intune configuration profiles.

Enforce Consistent Security: Control the Account Protection UI in Windows Security via Intune - Fig. 02

Allowed Values

The policy supports two possible values:

  • 0 (Default – Disabled): Users can see the Account Protection area in the Windows Security app.

  • 1 (Enabled): The Account Protection area is hidden from users in Windows Security.

When the value is set to 1, the UI is removed entirely, preventing users from viewing or attempting to change sensitive account-related security settings.

Enforce Consistent Security: Control the Account Protection UI in Windows Security via Intune - Fig. 03

Group Policy Mapping (Reference)

For environments that still rely on Group Policy or hybrid management models, this Intune CSP maps directly to the following Group Policy settings:

  • Policy Name: AccountProtection_UILockdown

  • Friendly Name: Hide the Account protection area

  • Location: Computer Configuration

Enforce Consistent Security: Control the Account Protection UI in Windows Security via Intune - Fig. 04

Enforce Consistent Security: Control the Account Protection UI in Windows Security via Intune

How to Configure Account Protection Area Visibility using Intune

You can centrally control the visibility of the Account Protection area in Windows Security using Intune, ensuring this setting is managed consistently across all devices and not left to user interaction.

To begin configuring this policy, sign in to the Microsoft Intune admin center and follow the steps below, as illustrated in the screenshot.

Step-by-Step Configuration (Intune)

  1. In the Microsoft Intune admin center, navigate to Endpoint security.

  2. Under Endpoint security, select Antivirus.

  3. Click + Create Policy to start creating a new security profile.

  4. In the Create a profile pane, set the Platform to Windows.

  5. For Profile, select Windows Security Experience.

  6. Click Create to proceed to the configuration settings.

At this point, you’ve created the foundation of a Windows Security Experience policy. In the next steps, you’ll configure the specific setting that controls the visibility of the Account Protection area and define how it is enforced across managed devices.

Enforce Consistent Security: Control the Account Protection UI in Windows Security via Intune - Fig. 05

Define Basic Profile Details

After clicking Create, the next step is to define the basic details of your Windows Security Experience policy. This includes providing a clear Name and a meaningful Description, which are critical for long-term management and operational clarity.

A well-defined name and description make it easier to identify the purpose of the policy later especially in environments with multiple security profiles or mature Intune implementations.

As shown in the screenshot, configure the fields as follows:

Suggested Name and Description

Name: Hide Account Protection UI in Windows Security

Description: This policy controls the visibility of the Account Protection area in the Windows Security app. When enabled, it hides the Account Protection section from end users, preventing them from viewing or attempting to modify account-related security settings that are centrally enforced through Intune.

This configuration helps maintain a consistent security posture across managed devices, reduces user confusion, minimizes help desk tickets, and ensures that organizational security policies remain intact.

Enforce Consistent Security: Control the Account Protection UI in Windows Security via Intune - Fig. 06

No changes are required for the Platform, as it is already pre-selected. Once the name and description are defined, click Next to continue to the configuration settings.

Configure the Disable Account Protection UI Policy (Default Behavior)

By default, the Disable Account Protection UI setting is configured as Not configured, as shown in the screenshot.

When this policy is Not configured or explicitly set to Disabled, the Account Protection area is visible by default in the Windows Security app. This means end users can see the Account Protection section in Windows Defender Security Center, even though the underlying security settings may already be enforced through Intune.

At this stage:

  • The Account Protection UI remains visible to users

  • No changes are made to security enforcement

  • Users can still view account-related security information

This default behavior is useful for environments that want full transparency, but it may not be ideal for organizations aiming for strict security governance and centralized control.

Enable the Policy to Hide the Account Protection UI

To hide the Account Protection area from end users, the policy must be explicitly enabled.

As illustrated in the screenshot, configure the setting Disable Account Protection UI and select:

Enable – The users cannot see the display of the Account protection area in Windows Defender Security Center

When this option is enabled:

  • Users can no longer see the Account Protection section in Windows Security

  • Account-related security settings remain active and enforced

  • All controls stay centrally managed by administrators through Intune

This configuration removes the Account Protection UI from view while ensuring that security protections continue to operate in the background without user interaction.

Enabling this setting is recommended for organizations that want to:

  • Enforce centralized security governance

  • Reduce user confusion

  • Prevent unnecessary interaction with restricted security areas

  • Maintain a clean and consistent Windows Security experience

Once the setting is selected, click Next to continue with the policy assignment.

Enforce Consistent Security: Control the Account Protection UI in Windows Security via Intune - Fig. 07

Configure Scope Tags (Optional)

Scope tags are used to control who can view and manage this policy within the Microsoft Intune admin center. They are especially useful in larger or delegated environments where administrative responsibilities are separated across different IT teams or regions.

As shown in the screenshot, the Default scope tag is selected. This is the standard behavior and is sufficient for most environments, as it allows the policy to be visible to all administrators who have access to Intune.

You can optionally assign custom scope tags if you need to:

  • Limit policy visibility to specific IT roles or teams

  • Enforce administrative separation

  • Support delegated or regional management models

If no additional scope tags are required, simply keep the Default selection and click Next to proceed.

Enforce Consistent Security: Control the Account Protection UI in Windows Security via Intune - Fig. 08

Assignments – Account Protection Area Visibility Policy

After configuring the policy settings, the next step is to assign the Account Protection Area Visibility policy to the appropriate target group. Assignments determine which devices will receive and enforce this configuration, ensuring the policy is applied only where intended.

In the Assignments tab, use the Search by group name field to quickly locate the group you want to target. This makes it easy to apply the policy in controlled phases or to specific test or production groups.

As shown in the screenshot, select the desired group. In this example, the policy is assigned to:

GRP – MS365Education – Test Computers

Once the group is selected:

  • Ensure the Target type is set to Include

  • Confirm the correct group appears in the assignment list

After selecting the group, click Next to continue to the final review step.

Enforce Consistent Security: Control the Account Protection UI in Windows Security via Intune - Fig. 09

Review + Create – Final Validation

In the Review + Create step, take a moment to validate all configured settings before deploying the policy.

By default, this section is displayed in a collapsed view, as shown in the first screenshot. To review the details, simply expand each section, as demonstrated in the second screenshot.

Carefully verify the following items:

  • Policy name and description

  • Configured settings (Disable Account Protection UI enabled)

  • Scope tags assigned

  • Assignments, including the correct target group

This final review ensures that the policy is correctly configured and aligned with your security and deployment strategy.

Once everything has been confirmed and validated, click Create (or Save) to finalize and deploy the policy to the assigned devices.

Enforce Consistent Security: Control the Account Protection UI in Windows Security via Intune - Fig. 10
Enforce Consistent Security: Control the Account Protection UI in Windows Security via Intune - Fig. 11

Monitor Policy Deployment Status

After creating and assigning the Hide Account Protection UI in Windows Security policy, the final step is to monitor its deployment and confirm that the configuration has been successfully applied to the targeted devices.

By default, Intune policy propagation can take up to several hours. If needed, you can speed up the process by triggering a manual sync from the device (via Company Portal) or by initiating a sync directly from the Intune admin center.

How to Verify Deployment Status

Follow these steps to validate the policy deployment:

  1. In the Microsoft Intune admin center, navigate to: Endpoint security ➝ Antivirus

  2. Locate the policy Hide Account Protection UI in Windows Security in the policy list

  3. Click the policy name to open its overview page

  4. Review the Device and user check-in status section

Enforce Consistent Security: Control the Account Protection UI in Windows Security via Intune - Fig. 12

As shown in the screenshot, you can see the overall status summary, which confirms that the policy has been successfully applied:

  • Succeeded: 2

  • Error: 0

  • Conflict: 0

  • Not applicable: 0

  • In progress: 0

This confirms that there are no deployment issues and that the policy is being enforced correctly on all targeted devices.

Enforce Consistent Security: Control the Account Protection UI in Windows Security via Intune - Fig. 13

Why This Matters

Monitoring policy status allows administrators to:

  • Quickly validate successful deployment

  • Identify and troubleshoot errors or conflicts

  • Ensure consistent security posture across managed devices

This visibility is essential for maintaining confidence in your Intune security configurations and for taking immediate action if any device falls out of compliance.

Client-Side Verification via Event Viewer

After the device syncs with Microsoft Intune either automatically or through a manual sync you can confirm that the DisableAccountProtectionUI policy has been successfully applied directly on the client device using Event Viewer.

This verification method is extremely useful for troubleshooting, auditing, and validating security configurations, especially in enterprise or regulated environments.

How to Verify Policy Application

  1. Open Event Viewer on the target Windows device

  2. Navigate to: Applications and Services Logs ➝ Microsoft ➝ Windows ➝ DeviceManagement-Enterprise-Diagnostics-Provider ➝ Admin

  3. In the right-hand pane, select Filter Current Log

  4. Look for Event ID 813 or 814, which typically indicates successful processing of Intune configuration policies

  5. Open the event details and confirm the following information:

The Int value (0x1) confirms that the policy is enabled, meaning the Account Protection UI is hidden in the Windows Security app while the underlying security controls remain active and managed by Intune.

You may also see additional metadata such as Enrollment ID, User SID, and Scope, depending on how the device was enrolled and how the policy was assigned.

Pro Tip

Always verify that the event timestamp aligns with the most recent device sync. This client-side validation is one of the most reliable methods to confirm Intune policy enforcement especially when investigating delayed deployments or unexpected behavior.

More Information

For additional technical details, official documentation, and deeper insights into this policy and related Intune concepts, refer to the Microsoft Learn resources below:

 

 

Thank you!

🖥️ Ricardo Barbosa

🎖️ Microsoft MVP | 📘 Microsoft Certified Trainer (MCT)

☁️ Intune & Cloud Architect |💼 Technology Director at Altelix.com

 

Originally published on LinkedIn · January 19, 2026 · read the original article
Tags:
MicrosoftIntune
EndpointManagement
Windows11
DeviceManagement
ModernWorkplace
MEM
ITPro
ZeroTrust
MVPBuzz
Keep reading

The full Hardening Windows Endpoints series

One control at a time, with the exact policy paths, the detection and remediation scripts, and the reporting to prove it worked across the fleet.

Browse all articles
Need a hand

Rolling this out across a real fleet?

Reading the guide is the easy part. Designing it for thousands of devices, piloting it without breaking production and proving compliance afterwards is the hard part. That is what we do at ISolutions CloudX.

Talk to ISolutions CloudX

Written by Ricardo Barbosa, Microsoft MVP and MCT. New guide every Wednesday and Friday. Follow on LinkedIn to get the next one.

Posts Sugeridos

Enforce Consistent Security: Control the Account Protection UI in Windows Security via Intune | CyberCloudOps Blog