Four high school students hacked 500 screens across campus as graduation prank
wired.com
wired.com
Systems need to move to role based security, where you are logging as user X who can do Y. Then the effort can spent securing the central log in system.
An admins password (not our team) being leaked is exactly what hapened to our client with the most effective federation, and the consequences were disastrous. They have now recovered, but are considering other options and potentially going back to machine-specific passwords to ensure only one gets compromised at a time.
There does need to be a bootstrap phase to register the device the first time, but beyond that, access should be time limited and device specific.