When it comes to protecting against credentials theft on Windows, enabling LSA Protection (a.k.a. RunAsPPL) on LSASS may be considered as the very first recommendation to implement. But do you really know what a PPL is ?
https://itm4n.github.io/lsass-runasppl/
Comme le soleil, les machines ne se couchent jamais.