Users Guide

You can bypass the UAC restrictions by:
Enabling remote agent use of the Local System Account to perform a DUP update. The Local System Account is not protected by UAC
(recommended option).
Using the Local Administrator Account on each remote machine where the DUP is running.
Disabling UAC for all users on remote machines (not a recommended option).
Not upgrading to Administrator account on remote machines.
NOTE: Only two accounts (the Local Administrator Account and the Local System Account) are not protected by UAC. All other
users including accounts with local administrator rights or domain administrator rights have UAC enabled by default. Even though
UAC can be disabled by updating the local or domain security policy, it is not recommended. Remote users have to login as a
built-in Local Administrator Account or obtain the Local System Account privilege to launch a DUP remotely.
38 Microsoft Windows Server 2008 User Account Control