Create a Developers Built-In Group
Create a built-in group "Developers" on Windows Server (and domain controllers) and restrict the activity of those users to compile, debug and run their applications. If the developers computer gets compromised then the damage is limited. Unfortunately the effort to restrict "developer" accounts is too error prone.
Following the convention of least privilege, application developers need not be a full blown administrators on their development machines. For example, they don't need to mange users, groups, memberships or even be able to make changes that effect everyone on the host. They do need the ability to compile and debug their software.
Similar to Azure, create roles (aka groups), that would better control what developers can do.