LWMadmin Agent for Windows

Create a new Agent in the authenticated LWMadmin cabinet and copy the generated
Windows x86_64 PowerShell command. Run that command from PowerShell as Administrator.
The generated command contains the one-time enrollment code and Server URL and waits
for credential.json so a failed enrollment is visible immediately.

The outbound LWMAdminAgent service always runs as LocalService. A separate
LWMAdminPrivilegedBroker service runs as LocalSystem, binds only to loopback and
receives only explicit privilege=root requests after Server-side root_access policy.
Do not switch the outbound Agent itself to LocalSystem.
