AD directory admins group setup Recently I have been reading many of the Microsoft Active Directory best practices for security and hardening. These are great resources, and very well written. The major theme of the articles is "least privilege", where accounts like Administrators or Domain Admins are over used and lead to further compromise. A suggestion that is put forward by the author is to have a group that has no other permissions but to manage the directory service. This should be used...