The client token at least needs to have the SecurityImpersonationLevel of at least Impersonation for Out of process Webhost ...