Microsoft AD DS domain controllers are administered using dedicated domain administrator user accounts that are not used to administer other systems.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.