Very interesting post by Microsoft about the internals of the new Admin Protection feature
It seems they have patched my SSPI UAC bypass based on NTLM as well as the Kerberos UAC bypass in which both were able to bypass AP as well
More details here 👇
Looks like this mitigation was added in 1803, build 17134.
It would be sad 😸 if someone would seamlessly 𝐛𝐫𝐞𝐚𝐤 𝐢𝐭 via user-writeable subkeys under the "\Registry\Machine".
Like, you know, HKLM\System\CurrentControlSet\Control\Nsi\{eb004a1c-9b1a-11d4-9123-0050047759bc}\0.