During an acquisition integration, you discover the target company grants domain administrator privileges to its entire 12-person IT department. They argue the small team requires broad access for operational efficiency. Your organization's policy enforces least privilege. What should you do FIRST?
A. Immediately revoke domain admin from all subsidiary IT staff and assign role-based access
B. Conduct a privileged access audit to map which admin functions each role actually requires
C. Allow current access with enhanced monitoring until integration is complete
D. Require the subsidiary to adopt your identity governance platform before network integration