01: Which account does an elevated process run within?

PolicyPak Least Privilege Manager does not need a special user to perform elevation, nor does it create some kind of “temporary admin.”

All process elevation is handled in the context of the actual user to which the rule applies.

The context is still the USER and all activity happens in the user profile (in this example EastSalesUser1).

But the PROCESS is elevated. Here’s an example running UAC-Required PowerPointViewer.exe installer with EastSalesUser1 when a PolicyPak Least Privilege Manager rule is in place to affect EastSalesUser1.

  • 920
  • 09-Nov-2021