Tiered administration separates privilege contexts

The core idea is simple: a credential that controls everything should never be typed into a machine that is not equally protected.

Administrators get separate accounts for separate tiers, and the powerful ones are only ever used from hardened systems. It is the single most effective structural defence against the pattern where one phished workstation ends up with domain administrator. It is also disruptive to adopt, which is why it is widely recommended and unevenly implemented.

More on Windows and Active Directory