This privilege determines which user accounts can modify the integrity label of objects, such as files, registry keys, or processes owned by other users. Processes running under a user account can modify the label of an object owned by that user to a lower level without this privilege.
When configuring a user right in the SCM enter a comma delimited list of accounts. Accounts can be either local ...