best practices: builtin administrator account in AD

From: mocity (mocity_at_discussions.microsoft.com)
Date: 05/25/05

  • Next message: Robin: "XP client & Server authentication"
    Date: Tue, 24 May 2005 19:45:10 -0700
    
    

    Hi,
    I understand that renaming the builtin AD administrator account is a good
    idea, but is disabling this account and additional good security measure? I
    would have no problem disabling this account, except for the fact if all
    other Domain Administrative accounts got locked out I would have no way of
    logging to the domain with admin privileges except through rebooting a DC
    into Safe Mode which enables the builtin administrator account---but this
    would be a hassle. (i'm sort of paranoid of a scenario where a malicious user
    locked out all my admin accounts, and me having to do this).
    is having this account enabled a security risk, because it cannot be locked
    and thus gives a person infinite attempts at cracking the password?
    thanks.


  • Next message: Robin: "XP client & Server authentication"

    Relevant Pages

    • Re: Want to restrict teenagers ability to download programs etc
      ... The standard security practice is to rename the account, set a strong password on it, and use it only to create another account for regular use, reserving the Administrator account as a "back door" in case something corrupts your regular account. ... HOW TO Use the Internet Explorer 6 Content Advisor to Control Access ...
      (microsoft.public.windowsxp.security_admin)
    • Re: Vista Security Problem
      ... Have you changed any security permissions on files recently? ... Using the built-in administrator account, start the local group policy editor for both the local computer and your normal username: ... > running yet I cannot find the security service in admin tools/computer ...
      (microsoft.public.windows.vista.general)
    • Re: Can not figure out why?
      ... If you changed the account name without re-establishing all of your network sessions the PC where you logged in is going to be sending cached credentials that conflict with what's now stored on the domain controllers. ... Want some good security information? ... > Logon Failure: ... > I checked all service and none of service uses administrator account ...
      (microsoft.public.windows.server.active_directory)
    • Re: XP network error
      ... The account is not authorized to log on from ... Disabling NIS may not be sufficient. ... When you disable Simple File Sharing, do you have a working Guest ... Security Policy. ...
      (microsoft.public.windowsxp.network_web)
    • Re: local administrator account password policy
      ... so I guess disabling those accounts in XP and ... >> have much less risk of local administrator passwords being compromised as ... >> issue those users that need local administrator account access smart ...
      (microsoft.public.windows.server.security)

  • Quantcast