RMM running as SYSTEM is break-glass access for when the domain itself is compromised — it's the one thing an insider can't easily reach if they're not in your RMM tenant.
Takeaway
we now deploy this script as part of every client onboarding, so a break-glass local admin exists on every endpoint from day one.
Takeaway
unique passwords per machine stop lateral movement cold — one compromise is one machine, not the whole fleet.
Takeaway
insider threats can't disable what they don't control; keep your management plane outside the client's identity provider.