AD Domain Controller with non-admin owner

A non-administrator owning an AD Domain Controller poses a significant risk due to potential privilege escalation through unauthorized group membership, exposing attack paths and administrative scope.
Privileged group members with weak password policy

Weak passwords in privileged group members expose accounts to authentication bypass, enabling attackers to gain unauthorized access.