In my organisation there are several advanced users and an overall need to be local administrator.
I have noticed that some users remove the Domain Admins group from the Local administrators group and use the local account for work and map up network drives.
Any suggestion how to prevent this from happening?