Risks of Local Admin access?

From: David L. Caldwell (dlcaldwell@netscape.net)
Date: 02/20/03


From: David L. Caldwell <dlcaldwell@netscape.net>
Date: Thu, 20 Feb 2003 11:04:48 -0800


Hello Everyone,
 How and where does Windows 2000/XP store cached
password? What is the chance a user with local admin access can read
and try to break those passwords? I am rolling out Active Directory in
our area. Unfortunately, many of the software programs the users need
require them to have local Admin access to the computer. I?m concerned
they may able to gain access to other people?s passwords ? especially
passwords of our domain admin staff. Are there any other potential
security risks when users have local admin access to computers on an
Active Directory domain?
 Any insights would be greatly appreciated.

Thanks,

--Dave

---------------------------------- David L.
Caldwell
College of Engineering
University of Delaware



Relevant Pages

  • Risks of Local Admin Access on Domain PC?
    ... How and where does Windows 2000/XP store cached passwords? ... What is the chance a user with local admin access can read and ... programs the users need require them to have local Admin access ... Active Directory domain? ...
    (microsoft.public.security)
  • Re: Risks of Local Admin Access on Domain PC?
    ... there are lots of risks - and cached credentials aren't the biggest (at ... > How and where does Windows 2000/XP store cached passwords? ... > programs the users need require them to have local Admin access ...
    (microsoft.public.security)
  • Re: Risks of Local Admin Access on Domain PC?
    ... AFAIK the attack you describe is not a common attack. ... It may be wise to restrict the administrator of a machine to just the ... > How and where does Windows 2000/XP store cached passwords? ... > programs the users need require them to have local Admin access ...
    (microsoft.public.security)
  • Re: Risks of Local Admin Access on Domain PC?
    ... I beleive in an AD enviro the passwords are stored in the registry. ... > programs the users need require them to have local Admin access ... > Active Directory domain? ...
    (microsoft.public.security)
  • Re: Using Sharepoint as an Extranet?
    ... Is _is_ only available under Active Directory Account Creation Mode. ... > Administrators can change user passwords after clicking on VIEW ...
    (microsoft.public.sharepoint.windowsservices)