The only real way to defend against this attack is to only allow domain admins to log into domain controllers, not lower privileged machines!