The PAStandardUser local account on the client is used by the Privileged Application Discovery component.
It is used to determine if an Application launched on a client would fail if it needs Administrative privileges to start normally.
Once a privileged process has started (or failed to start) on a client computer, the corresponding information
will be sent to the server and display in the Privileged Application Discovery section of the console (provided
that your environment is properly configured according to the Maximum Sleep Time setting).
You can only view data stored in the database of the server that is selected in the server configuration (Setup
Tasks > Configure a Server).
When processing a discovered privileged application, you can either create a rule for it so that a user without
elevated privileges can launch it, or choose to mark it as processed so that it will not display in the list (unless
the filter is specifically set to display it).
Use the Generate Rules wizard to automatically create a number of rules for different types of applications in one pass.
Rules are created based on the preferences with which the application was started. You can select an application and view its preferences in the Privileged Applications Discovered grid.
Also, the account gets created by default when the client is installed.
We are not aware of a way to stop the account from being created.
In addition, if the account is deleted, it gets recreated when the Scriptlogic Privilege Authority Host Service is restarted service is restarted.
Finally, the account may be disabled if it is not being used by the functionality listed above.