Your network contains an Active Directory domain named contoso.com. The domain contains five servers.
All servers run Windows Server 2016.
A new security policy states that you must modify the infrastructure to meet the following requirements:
Limit the rights of administrators.

Minimize the attack surface of the forest.

Support Multi-Factor authentication for administrators.

You need to recommend a solution that meets the new security policy requirements.
What should you recommend deploying?