Groups like Enterprise Admins, Schema Admins, and Domain Admins shouldn't have any permanent members.
All participation in these security organizations should ideally be momentary and only granted when absolutely necessary.
#windowsActiveDirectory #Security