To minimize potential points of attack, local user accounts, other than built-in accounts and local administrator accounts, must not exist on a workstation in a domain. Users must log on to workstations in a domain with their domain accounts.
Check
Run "Computer Management". Navigate to System Tools >> Local Users and Groups >> Users.
If local users other than the accounts listed below exist on a workstation in a domain, this is a finding.
For standalone or nondomain-joined systems, this is Not Applicable.