Since a long time ago, I use my main account as a standard one, plus an admin one that I use to elevate though UAC. I also made the UAC popup purposefully difficult to use (having to type both user and password) to prevent me elevating everything with a click, thus thinking twice before each run as admin. Most work don't really requires admin elevantion anyway.
The built-in administrator is left as a last resort for some rescue tasks or heavy management, but sits mostly unused.
I've also tried to put a third account, a standard one that I only use to run the most sensitive and vulnerable programs, for example the browser and mail clients. A bit cumbersome to use, but doable and adds a little more security, an idea I got from Android actually.
My wife uses the same account pair whenever she uses the same computer. I also left an extra account for any visitors that may happen to use the computer (my nephew for example for watching youtube and a game or two).
For a few services I also create dedicated accounts, or use the built-in service accounts. Nothing runs as system if possible.
Of course, every single account is local, nothing should ever be a MS account.