A municipal IT group places Domain Admin rights on many day-to-day admin accounts. What finding theme should the tester raise?
Select an answer to reveal the explanation.
Short Explanation
Domain Admin is a master key, not a daily coffee badge. When half the helpdesk carries that key for email and spreadsheets, one phish becomes an empire-wide problem. Shrink the privileged club.
Full Explanation
Over-membership in Domain Admins or equivalent groups expands the impact of any single compromised account. Least-privilege and tiered administration models exist specifically to reduce that blast radius. Active Directory does not require broad day-to-day Domain Admin use, and privileged group sprawl does not itself enable unrelated controls like BitLocker. Reporting excessive privileged membership is a core AD hygiene finding.