If you enable local admin accounts, for users that require them, you should also enforce a set of policies to ensure the local accounts have strong authentication standards. On domain joined computers, Group Policy can be used to specify the settings of the local account policy, which contains two subsets:
- Password Policy: These policy settings determine the controls for local account passwords, such as enforcement and lifetimes
- Account Lockout Policy: These policy settings determine the circumstances and length of time for which an account will be locked out of the system when the password is entered incorrectly