These days security teams know that the vast majority of malware and attacks exploit privilege and user rights to gain the necessary level of network access or achieve lateral movement. Once an application, malware, or user gains administrative rights, they can effectively do anything to the system. As administrative rights have not yet evolved enough to be secure, the most effective approach is to remove administrative rights everywhere possible: make everyone a standard user and handle tasks that require elevated privileges as an exception, not the norm.

