Our internet security boss wants "ALL" internal directory accounts removed. We use an LDAP directory (read-only with local groups). As the system admin, I have my LDAP account, but also two internal directory accounts used for access when the corporate exchange server is offline or when I need to replicate the permissions of another user's account to provide troubleshooting assistance.