Re: administrator

From: Steven L Umbach (n9rou_at_nospam-comcast.net)
Date: 10/21/05


Date: Fri, 21 Oct 2005 12:14:32 -0500

You have to be careful for any account that is subject to password maximum
age and is configured for password can not be changed as the user will not
be able to change the password if they wait until the password has expired
and an administrator will have to manually reset the password.

I don't have a link to a recommendation why it should never be used but
generally the password can not be changed attribute is used where users
share an account and do not lock a user out when the password is changed or
when an account is used for services which you would not want to use the
built in administrator account for so I don't see a good reason to implement
it on the built in administrator account. Keep in mind that the can not
change password attribute only prevents the user from "changing" the
password and does not prevent domain level administrators from resetting the
password. --- Steve

"frank" <frank@discussions.microsoft.com> wrote in message
news:73590776-C4CF-45A7-AF5D-653FBB483ACF@microsoft.com...
> Our company had a recent audit and part of the report explain the
> administrator accounts needs to renamed and set to change password
> I have renamed but I am hesitating on uncheck never change password is
> there
> a link which show why/why not it should be set at never change password
>
>
> Thanks for the help
>



Relevant Pages

  • Re: Basic Authentication + IIS 5 + Windows 2000 + Frontpage 2002 = failure?
    ... administrator account -- we should have no problems at least browsing to ... server. ... | authentication dialog box. ...
    (microsoft.public.inetserver.iis.security)
  • Re: Serious Security & Administrative issue!!!!
    ... capability [including file encryption and a boatload of security policies] to be ... The concept of the built in administrator account is ... if that account is only available in safe mode then hackers can not use it ...
    (microsoft.public.security)
  • RE: [VulnWatch] Blank Administrator password in DELL XP Professional install
    ... default out of the box configuration for any Windows XP Pro, ... this can lead to security ... risks if the administrator disables the account. ... Null Password on Administrator account. ...
    (VulnWatch)
  • Re: Where did my User account go? More Info
    ... rebooted machine, the Administrator account shows up, ... the built in Administrator account is hidden. ...
    (microsoft.public.windowsxp.general)
  • Re: Update Error Code 800B0100 P.P.S.
    ... Here is the Direct link for that download for Vista x86 systems ... Administrator account that has full admin rights that could address those Windows updates that are not able to install. ... If the happens to be the built-in Administrator account, then enable it and set a password for it and login with the Administrator account. ...
    (microsoft.public.windows.vista.general)