RE: On the topic of Windows Hardening

From: Ben Conrad (BConrad_at_merklenet.com)
Date: 11/14/05

  • Next message: Kurt Dillard: "RE: What server hardening are you doing these days?"
    To: Peter Hyvonen <phyvonen@selfcharge.com>, focus-ms@securityfocus.com
    Date: Mon, 14 Nov 2005 13:49:22 -0500
    
    

    Usually, having a domain/local user in the local "administrators" group will
    be a solution to this issue. If you want to rename the Administrator
    account, you can do so, however it's always going to be the original
    Administrator account based on it's local SID (ends in 500). So you can
    rename it to Bob and create a new account that is in the local
    administrators group named Administrator if you wish.

    Ben

    -----Original Message-----
    From: Peter Hyvonen [mailto:phyvonen@selfcharge.com]
    Sent: Friday, November 11, 2005 6:18 PM
    To: focus-ms@securityfocus.com
    Subject: On the topic of Windows Hardening

    Its there a way to 'fake' an administrator account? I ask because our
    MRP software requires the user have complete local privliges (power user
    accounts do not work) I've complained but changing MRP software is not
    an option. We have alot of small fires because the users of the MRP
    software have to be administrator on their own box. Thanks in advance

    Pete Hyvonen
    Systems Specialist
    Self Charge Inc.

    ---------------------------------------------------------------------------
    ---------------------------------------------------------------------------

    ---------------------------------------------------------------------------
    ---------------------------------------------------------------------------


  • Next message: Kurt Dillard: "RE: What server hardening are you doing these days?"

    Relevant Pages

    • Re: Can I clone Administrator?
      ... you don't want to rename the profile folder. ... >> also rename the Administrator folder in Documents and Settings. ... >>> You should always, ALWAYS, have a second administrator account. ...
      (microsoft.public.windowsxp.security_admin)
    • Re: Can I clone Administrator?
      ... you don't want to rename the profile folder. ... > also rename the Administrator folder in Documents and Settings. ... >> You should always, ALWAYS, have a second administrator account. ...
      (microsoft.public.windowsxp.security_admin)
    • Re: Event 1202 Warnings after Renaming Administrator Acct on SBS2003
      ... policy to rename the account although it is not really necessary or useful. ... Did I check Group Policies for references to the Administrator ... Failed to perform redirection of folder Desktop. ...
      (microsoft.public.windows.server.general)
    • Event 1202 Warnings after Renaming Administrator Acct on SBS2003
      ... one referencing the original administrator account: ... specific policy setting that was flagged with a big, ... I used an incorrect procedure to rename the ...
      (microsoft.public.windows.server.general)
    • Re: Event 1202 Warnings after Renaming Administrator Acct on SBS2003
      ... Did you check the Group Policies for references to the Administrator ... Administrator account? ... what policy do you have? ... referencing the former administrator account. ...
      (microsoft.public.windows.server.general)