Update Appendix-G--Securing-Administrators-Groups-in-Active-Directory.md #8001
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
The document says "There should be no day-to-day user accounts in the Administrators group with the exception of the Built-in Administrator account for the domain". But it also says "Additionally, DAs and EAs inherit a number of their rights and permissions by virtue of their default membership in the Administrators group. Default group nesting for privileged groups in Active Directory should not be modified".
This is unclear and possibly contradictory. The term "day-to-day user accounts" is not defined or standard. Does it include the Administrator account and the DA and EA groups? If it does, then the part about not modifying nesting groups is contradictory. If it does not, then the Administrator account cannot be excluded, because it is not included.
It is not clear whether the intention is to remove ALL members, with the possible exception of the Administrators account; or to remove ALL members EXCEPT the default members.