Why would two devices in the same OU have UAC prompting differently?

Posted by This_guy_works@reddit | sysadmin | View on Reddit | 9 comments

I created a test OU in AD for two of my PC's I am working with. I created a GPO for that group with user account control settings to prompt for credentials whenever something requiring administrator rights is ran. I am using an HP desktop and an HP laptop. The laptop works great after moving it to the OU and updating the group policy - When anything requiring admin rights comes up, it will darken the screen and prompt for admin credentials to run. However, on the desktop with the same user account logged in and in the same OU, it will darken the screen and give prompt to continue, but not ask for credentials. Just allow or deny. I am finding this very bizarre. Prior to moving to this OU, both devices ran everything without prompting/warning, which is the current standard, and I could install anything. For obvious reasons I want to enable UAC controls so standard users cannot do admin tasks without proper credentials. I am just not sure why the laptop is working as intended, but the desktop is not. Both devices are running the same version of Windows 10 (22H2) and both are logged in with the same user account and both have had their group policy updated and been restarted. Both of them are showing up the same results in the local group policy editor as having the same UAC settings enabled under computer configuration > windows settings > security settings > local policies > Security Options. I'm just not sure where to go next on this one. The only other clue I have is that the desktop was imaged a month ago, and the laptop was just imaged a couple days ago and joined to the domain. Is it possible there might be something overriding UAC or group policy in the older setup that isn't there on a fresh install/domain join?