So I just went back and had a quick look at this (using off the shelf USB devices -> get SYSTEM from local non-admin user) and discovered a way to do it on remote systems using RDP.
Better still, you don’t need the actual USB device - you can just spoof the device. Also it’s enabled out the box and feature is turned on by default.