A system for providing application services in a computing environment
having both user-mode processes and privileged-mode processes. A
user-mode component is provided with an interface configured to access an
exposed privileged-mode interface. A configuration component specifies a
list of installable code components that are authorized for installation,
wherein privileged-mode functions will only be executed in response to
accesses by the user-mode code component when the installable code
component is represented on the list.