Domain Admin is a forest-scale key
In a Windows environment, domain administrator is not an account. It is effectively the keys to everything.
It can reach every machine, read every credential and alter the rules that govern all of them. Which is why attackers aim for it specifically and why using it for routine work is so dangerous: every machine it logs into gets a copy of something worth stealing. Treating it as an ordinary administrative account is how one workstation becomes the whole estate.
More on Windows and Active Directory
- Kerberos tickets are credentialsWhoever holds it, gets in
- Golden Ticket attacks target the ticket authorityThey took the press, not a ticket
- Group Policy is a fleet control planeOne dial, every desk
- LAPS reduces shared local-admin secretsOne secret, or one each
- NTLM fallback preserves older trust assumptionsThe hatch nobody bricked up
- Service accounts can become invisible administratorsThe pass with no face
