Language:
Despite the number of Active Directory assets, the Domain Controllers are the most sensitive as they store all of these assets data (including authentication secrets like the users' passwords).
Only legitimate administrative accounts should be able to manage them.
The Domain Controllers (DCs) require strict access rights. Allow only highly privileged user accounts to manage DC objects or link new group policies.
Securing Active Directory Administrative Groups and Accounts
Name: Domain Controllers Managed by Illegitimate Users
Codename: C-DC-ACCESS-CONSISTENCY
Severity: Critical