For something like the scenario you mentioned, you should create a group that only has the permissions necessary to perform WMIC queries (or whatever it is you need to do). Then, create restricted user accounts and add them to that group as necessary. You don't need to be a domain admin to perform those types of activities. It's just easy and convenient to use domain admins for everything, and people are lazy.
The day you stop learning is the day you start becoming obsolete.