Re: How to secure the Administrator account?

From: Chuck (cacrollthespam_at_yahoo.com)
Date: 10/26/03


Date: 26 Oct 2003 11:07:07 -0600

On Sun, 26 Oct 2003 07:40:55 -0800, "David M. Streb, MCSE"
<exiis@hotmail.com> wrote:

>Here's a question I've never really investigated until recently; I'm hoping
>I'm missing something...
>
>Administrator Account: We regularly rename and place strong passwords onto
>this account. This account is limited to the most trusted employee of the
>company and never to the normal "administrator" of the network.
>
>Domain Admins: This is the regular, day-to-day account we assign to the
>full-time administrator.
>
>Problem: Members of the "Domain Admins" group are permitted to rename,
>reset, and change the "Administrator" account, as well as change group
>membership for both the "Administrators" and the "Domain Admins" members. In
>other words, a lower, less-trusted administrator is free to whatever he
>feels to the most trusted account--it doesn't make sense.

1) As you pointed out, your employees have to have system authority
necessary to do their job, balancing the need to maintain network
access against the need to keep the network secure.

2) You have to have employees you can trust, and a written security
policy to let them know what they may and may not do.

3) You have to have an audit trail you can trust, and review the
audit reports frequently enough that you see all events that concern
you, promptly enough to take action effectively.

4) You have to put the fear into your employees, and fire the first
who violates security policy.

Chuck
I hate spam - PLEASE get rid of the spam before emailing me!
Paranoia comes from experience - and is not necessarily a bad thing.



Relevant Pages

  • Re: How to secure the Administrator account?
    ... >>Administrator Account: We regularly rename and place strong passwords ... >>company and never to the normal "administrator" of the network. ... > 1) As you pointed out, your employees have to have system authority ...
    (microsoft.public.win2000.security)
  • Re: xp home admin password
    ... "matt" wrote in message ... yes one of my employees has gone on vacation and will be ... administrator rights on a computer that i have set up for ... fix my account to have administrator abilities? ...
    (microsoft.public.windowsxp.accessibility)
  • Re: How to secure the Administrator account?
    ... Seems silly to even have a Domain Admin account... ... >>company and never to the normal "administrator" of the network. ... >>Domain Admins: This is the regular, day-to-day account we assign to the ... > 1) As you pointed out, your employees have to have system authority ...
    (microsoft.public.win2000.security)
  • xp home admin password
    ... yes one of my employees has gone on vacation and will be ... administrator rights on a computer that i have set up for ... fix my account to have administrator abilities? ...
    (microsoft.public.windowsxp.accessibility)
  • Re: Event 1202 Warnings after Renaming Administrator Acct on SBS2003
    ... policy to rename the account although it is not really necessary or useful. ... Did I check Group Policies for references to the Administrator ... Failed to perform redirection of folder Desktop. ...
    (microsoft.public.windows.server.general)

Quantcast