Instead of requiring the end-user to create a domain admin, Liongard could create and manage it's own MSA/gMSA eliminating the need for yet another privileged account to be managed by administrators and increase overall security. https://docs.microsoft.com/en-us/windows-server/security/group-managed-service-accounts/group-managed-service-accounts-overviewhttps://docs.microsoft.com/en-us/azure/active-directory/fundamentals/service-accounts-group-managedhttps://www.varonis.com/blog/gmsa