Pass-The-Hash attacks exist and the only real countermeasure is to never log into user machines with privileged credentials
Of course kerberos tickets can be abused too in a lot of fun ways, but on a modern network PTH is pretty much dead and a surefire way to raise a lot of alerts
(You are absolutely right that privileged accounts must never login on less privileged assets, however!)