I have to admit i just have a good laugh after reading the few posts above, as
@Andy Ful said most don't have a clue of what is SUA vs Admin purpose.
SUA is a restricted account made for daily use like surfing, watching videos, gaming, etc...
Admin account is for all ADMIN task: maintenance, drivers/softs/program/OS updates, etc...
the problem is that in the past decades, Microsoft stupidly set everybody to use an admin account by default, so devs of all sorts just used to program their software to be used on admin account when it was not necessary.
in enterprises, only the bad admin would use Admin account for others than himself, because admin are supposed to administrate, if they want browse, they use another computer or switch users.
those people should be fired, they are the ones why ransomware hit most companies/organizations so hard.
They are just lazy and refuse to adapt their working methodology for a safer environment.
before implementing, SRP you have to intensively test the policy. The admin was faulty because of ignorance and carelesssness, SRP isn't faulty, SRP is the best security mechanism if properly used. There is a reason why most 3rd party corporate products from kaspersky, McAffee, Symantec, Sophos all implement some kind of SRP.
If used without proper testing and implementation.
SRP isn't made for personal use, it is made for static systems like you have in corporate environment.
Notabot, i'm sorry to say that but your understanding and view of SRP is all wrong.