There is nothing better for account security than having a really good passphrase on the domain admin account and all of the domain user accounts.One of the practises we took to years back was creating a Group Policy Object (GPO) at the domain level and calling it the Default Domain Security Policy - MPECS.Into that GPO would go settings such as enabling encryption between domain members, server