Earlier quoted context omitted.
> If an admin elevation popup happens when you haven't triggered it then you probably know something is wrong. And most malware will not be able to install. Malware can still do a lot without "installation". Running as an unprivileged user, it can still do anything to/with the filesystem that the user would be able to do, and will (on most normal setups) be able to make outbound Internet connections without limitatio…
This is true but defense is a multi layered approach and even the built in Microsoft stuff (like Defender AV) have massively improved. I would argue most malware comes down to uneducated users doing the wrong thing - but that's a whole different can of worms :-)
This feels unnecessarily harsh. Those users are the victims of criminal activity. The protective controls could be a lot better.
Windows doesn't offer immutable local file versions to protect against ransomware running as a non-privileged user. It doesn't offer any protection if a single application suddenly starts to overwrite huge amounts of data.
Instead they choose to try and shove OneDrive down our throats as the only answer to ransomware protection.