The PAM Administrator would like to know how to set the GPO Option related to UAC. PAM documentation for the Windows Remote target connector states the following:
If User Access Control is enabled on the target server and the account for password management is a local administrator, the connector needs access to perform SMB and WMI operations. To give the connector access, add the LocalAccountTokenFilterPolicy registry setting to remove remote restrictions: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\LocalAccountTokenFilterPolicy = dword:00000001
Registry key LocalAccountTokenFilterPolicy can not be set through an explicit configuration option within the Group Policy Management Editor. Instead it needs to be set through the definition of a custom registry key property. Within the Group Policy Management Editor this can be done at the following location:
Action: UpdateHive: HKEY_LOCAL_MACHINEKey Path: SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System
Value Name: LocalAccountTokenFilterPolicyValue Type: REG_DWORDValue Data: 1
If the Windows Server is a standalone server (not joined to an AD domain), then you can modify the local security policy. If it joined a domain, then you will need to modify this from GPO at the domain controller.
If you select "Use the following account to force change password" and choose another admin account, then the password can be rotated multiple times a day even if the "Minimum password age" is set to 1.