Sometimes elevation as user still doesn’t work because it only applies locally to the machine. At times a user that can access network shares as an Admin is needed (ex. applying Intuit Lacerte updates, which also updates files on a network share. In order for this to work. I have to login to the machine as a Domain Admin, then apply the update. Think network workstation and file server, or Azure AVD and File Server. We need to be able to provide company level Domain admin User. It seems this could be be applied as a setting in portal for that Company / Location, and then have that as an option in the Approval process (or Rule)