I use ACLs to restrict access to mmc.exe to the admin account only. That way, lots of mmc things are not available to the attacker since I use the Standard account daily.
Print Spooler
BitLocker drive encryption service
Windows Biometric Service
AssignedAccessManager
Geolocation Service
Parental Controls
WalletService
Fax
Payments and NFC/SE Manager
Phone Service
Print Device Configuration Service
Sensor Service
Server
Shared PC Account Manager