Re: W2k3 - Recover from lost Domain Admin passwords

From: Ulf B. Simon-Weidner (nospam2-ulf_at_usw-consulting.com)
Date: 01/25/04


Date: Sun, 25 Jan 2004 17:56:39 +0100

Laura A. Robinson [MVP] says...
> circa Sun, 25 Jan 2004 00:33:43 +0100, in
> microsoft.public.windows.server.security, Ulf B. Simon-Weidner
> (nospam2-ulf@usw-consulting.com) said,
> > Hello Robert,
> >
> > your passwords are more easily compromised if you leave this whole open.
> >
> > If you are all for security, then I'd create a domain admin password which is
> > totally random, and something like 30-50 letters. Print it out, and put it into
> > a safe. Don't use the domain admin account, but create admin accounts which are
> > individual per user. Give them just the rights they need. Educate them not to
> > log on with their adminaccount, but their useraccount and use RunAs for
> > administrative Tasks. Change the domain admin account quite frequently - like
> > once a month (every other month should be OK as well, if you use about 50
> > letters). Treat the service accounts like your domain admin account.
> >
> Ulf, you're a man after my own heart. :-)
>
> Laura
>
:-)

Gruesse - Sincerely,

Ulf B. Simon-Weidner



Relevant Pages

  • Re: Desperately need help
    ... Do you have a backup admin account? ... log in as a domain admin. ... don't give out administrator passwords in the future. ...
    (microsoft.public.windowsxp.security_admin)
  • RE: software to control domain administrators
    ... Then they get into a mode on how they can limit Domain Admin access so ... disclose usernames and passwords to the Domain Admin. ... software to control domain administrators ... Is the Administrator account ever restricted? ...
    (Security-Basics)
  • Re: Dual Boot Server to get around not knowing passwords
    ... > We have a customer that does not know their Domain Admin or Local Admin ... > Passwords on a Windows ... > can gain access to the data, programs and Exchange Server. ... What are the potential problems? ...
    (microsoft.public.windows.server.general)
  • Re: VB.Net WMI Windows Server 2003
    ... The domain admin account should be able to perform this action. ... NotFound management exception indicates that the management object you are ... Please do not send e-mail directly to this alias. ...
    (microsoft.public.dotnet.languages.vb)
  • Re: VB.Net WMI Windows Server 2003
    ... The domain admin account should be able to perform this action. ... NotFound management exception indicates that the management object you are ... Please do not send e-mail directly to this alias. ...
    (microsoft.public.win32.programmer.wmi)