@amuse I guess it depends what kind of IR processes you're running. If its a classic internal IR team in a relatively complex on-premise environment I would say that your IR team probably don't need local admin or application admin rights to servers/apps but should have the ability to elevate to DA equivalent as well as isolate, freeze, export images from the hypervisor as well as escalate quickly. I don't think I've seen anyone do it in a repeatable safe way yet.
I think my question is how do you do this in a constrained manner? Its not appropriate to have domain admin/global admin, but there needs to be a way to enact general as of yet undefined actions in an environment which means that prescriptive "I must have helpdesk admin and security contributor" doesnt make sense as the scope is too limited for fly away incident response.
Maybe the answer is trust your tooling to proxy this level of access, such as an EDR disabling accounts at the behest of a user that has lower permission, or design automations in your tooling that have limited scopes but large impact with high auditability.