SECURITY: I NEED DOMAIN or LOCAL ADMIN FOR ______?!?
25 Years here. Nothing has changed.
Software vendor: we "require" admin privileges on a system for our (crappy) software to work.
It was especially bad in Windows Vista post "Trustworthy Computing" era. Microsoft changed a lot in the security paradigm. Which they and the G00g ended up breaking - I don't remember which one did it first: %LocalAppData% baby!
Me: ProcessMonitor & ProcessExplorer.
Fix? Folder & Registry permissions. Done.
One of my faves though was when a client wanted another IT firm to audit our setup there.
Other IT Firm (OITF): Our Audit Tool needs domain admin and the firewall turned off.
Me: Oh? What's the product.
OITF: It's Audit Package Very Good (APVG)
Me: Okay, give me a bit.
** I dig into Audit Package Very Good's web site and establish the baselines needed for it to run in the OS and across the network.
Me: Okay, we're ready for you.
** OITF starts their audit
OITF: WTF?!? We WANT THE FIREWALL OFF for APVG to work!
Me: Run it.
OITF: Huh?
Me: R.u.n. it.
OITF: Oh, it's working.
From there it would be a barrage of questions because they usually hadn't encountered such a tight network before.
In the end, we'd get an A for our setup across the board.
And, for the ones that actually understood what they just audited, that is their ego didn't get in the way, they'd ask for some time to learn about it to augment their own practices.
Myth: Service accounts need Domain Admin
Reality: They rarely do, it’s just the easy, lazy way to do things