Local admin changes the consequence of compromise

Whether a user is a local administrator decides how bad it is when they click the wrong thing.

Without it, malicious code runs as that user, which is bad. With it, it can disable security tooling, install persistence, read credentials from memory and reach further. Removing local admin is one of the highest-value and most resented changes available, and the resentment is why it so often does not happen.

More on Endpoint security