AD computer account that is a member of privileged groups

A compromised AD computer account in a privileged group enables persistent lateral movement within the domain.
AD Domain Controller with non-admin owner

A non-administrator owning an AD Domain Controller poses a significant risk due to potential privilege escalation through unauthorized group membership, exposing attack paths and administrative scope.