I am merely repeating what the product team recommends - all app
pool identities are local admins.
I do not like this; in fact, I blogged about it in B2TR about my
disappointment in app pools being admins. But, yes, if you carefully set
DCOM security, this can be overcome. I obviously try not to send new
administrators into dcomcnfg.exe