It is important to mention that "administrator" by name or group is just another name, it's only the microsoft defaults that allow it to do what it can do. It can be restricted like any other account/group. It may take some digging in support but there is a list of expectations of what these apps and services MUST be allowed to do that is what these IT departments really need. I got it once for ALC long ago and it's pretty lengthy, I'm sure tridium has one somewhere. Within the apps they are also doing a little better at error messages, these days when I install WebCTRL and launch SiteBuilder make one change to the web server and receive a message "unable to save changes" what that really means is the app was launched with so little permission it can't even update a config file within it's own install folder.