I didn't interpret OP's comment like that. I think he was saying you can't enforce the boundary at all even if users don't get tricked.
That's true on Linux because the sudo UI can trivially be MitM'd by malware. You can't do that on Windows so trivially.