In active directory, there is a single "Domain Admin" password. You can change the username (as described in MS' "Best Practices"), but once you have that, you have control over every server and workstation in the network. Combine that with the "hidden/system shares" (c$, d$, etc), and you have...