Having an administrator's credential would be the easiest way to achieve persistence in a machine. However, to make it harder for the blue team to detect us, we can manipulate unprivileged users, which usually won't be monitored as much as administrators, and grant them administrative privileges somehow.

Assign Group Memberships

Special Privileges and Security Descriptors

RID Hijacking

Executable Files

Hijacking File Associations

Creating backdoor services

Modifying existing services

Task Scheduler

Startup folder

Run / RunOnce

Winlogon

Logon scripts

Sticky Keys

Utilman

Using Web Shells