and make sure to revoke seDebugPrivilege from administrators on endpoints that must have local admins (or even any admin).
Dear lords is it ever hilarious to watch pentesters, redteams, and attackers flounder when all their tools just don't work for some reason. No normal user will ever need seDebug, only the most advanced IT folks or attackers!