well this might clear it up for you
http://msmvps.com/blogs/ulfbsimonweidner/archive/2005/03/08/37975.aspxas for why it is allowed ...it might be because if you have a single domain configuration and you are not linked to other domains then there might not be a problem with have both these roles in a single system