Personal anecdotes of working in IT; nothing is ran properly. People love to espouse shit like least privilege access and making sure security controls are in place; but in reality, they rarely are, especially the bigger an organization gets. Because eventually, someone is going to want (and somehow get) a special privilege, and someone hears about that and the bullshit expands until you have people who don't rate shit, being able to access shit they have no right to access. Other side is, whoever administers their AD doesn't want to do shit properly, so they just assign whatever to whoever, or give special access to their "Users" group, which by the way, anyone with a login is in that group.
Short answer: people are fucking lazy, especially IT people.