Ticket 5477 adds UAC detection to cc_mslsa.c. When the current process is running under a UAC limited token, access to the MSLSA is disabled. At some point KFW may implement a service or COM object that runs with elevation in order so that it can be used to provide proxy access to the LSA credential cache session keys.