if you wanted to, you could disable interactive logon, so then the program can only use the access to what it needs on the network and the privalages won't be abused as easily, that is what we do when we use symntec ghost.