The most convenient and efficient way to operate a bank is where everything you need for customers is in easy reach.
So why do we store cash and valuables in bank vaults and safety deposit boxes?
Because it would be insanely easy to steal!
…but with digital businesses, we somehow overlook this and allow/encourage putting business critical assets and the ability to access them (administrative credentials) out 'in the open' on BOYDs and regular corporate laptops where people do email and web browsing to any old sites.
Microsoft published guidance on securing privileged access (https://aka.ms/spa) including the use of privileged access workstations (https://aka.ms/PAW) to change this practice that puts your organization at risk.
Please read and follow this guidance to get these out of the reach of any casual attacker!