Comment Re:Cool idea but... (Score 2) 150
At my organization we have deployed NAC to block unauthorized devices, Vmware NSX, for micro segmentation, web and email content filters, DLP detection, email encryption and MS ATA.
No one has a Domain admin account and Administrators must grant themselves access to systems they need to work on every day and those permissions are reset when they leave for the day.
Our goal is to make sure any attacks are so noisy because of the restrictions so they will be detected.