Which principle of access control is most aligned with Microsoft's recommendation for Active Directory service accounts?
-
A
Grant service accounts Domain Admin rights for unrestricted access
-
B
Apply the principle of least privilege, granting only the permissions the service requires
-
C
Use a single shared administrator account for all services
-
D
Give service accounts Schema Admin rights by default