"C:/Program Files" is still the recommended place to install programs, and it requires admin privileges to write to. Some programs (ab)use C:\ProgramData for that purpose instead and therefore don't need admin privliges. But even with that hack, ultimately Windows still uses the https://xkcd.com/1200/ permission model. (Everything runs with full access to all your data.)
On Windows enabling access control is 4 clicks. The problem with enabling it by default is that every time MS tries to harden the defaults there is much weeping and wailing and gnashing of teeth