I'm a fan of a tiered approach, but it requires having a good data/access classification structure in place.In a well thought out deployment most users shouldn't need standing admin, and with a tool like JumpCloud you can elevate the user permission ...