Re: best practices: builtin administrator account in AD
From: Roger Abell (mvpNOSpam_at_asu.edu)
Date: 05/25/05
- Next message: Roger Abell: "Re: Dear Microsoft... Rebooting servers id NOT security.."
- Previous message: Peter Foldes: "Re: Can Someone please explain"
- In reply to: mocity: "best practices: builtin administrator account in AD"
- Next in thread: Steven L Umbach: "Re: best practices: builtin administrator account in AD"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Date: Wed, 25 May 2005 08:26:31 -0700
additionally . . .
While it will not stop login attempts if authentication interfaces are
exposed to where you believe these threats would arise . . .
it is possible to just deny network login to even the built-in admin
account, restricting it to local login usage, but be aware that this does
not control connection to most services, but would stop such as use of
the administrative shares.
-- Roger Abell Microsoft MVP (Windows Security) MCSE (W2k3,W2k,Nt4) MCDBA "mocity" <mocity@discussions.microsoft.com> wrote in message news:EB7BFBE9-A467-4BC3-8F1F-6284EF9A3DE9@microsoft.com... > Hi, > I understand that renaming the builtin AD administrator account is a good > idea, but is disabling this account and additional good security measure? I > would have no problem disabling this account, except for the fact if all > other Domain Administrative accounts got locked out I would have no way of > logging to the domain with admin privileges except through rebooting a DC > into Safe Mode which enables the builtin administrator account---but this > would be a hassle. (i'm sort of paranoid of a scenario where a malicious user > locked out all my admin accounts, and me having to do this). > is having this account enabled a security risk, because it cannot be locked > and thus gives a person infinite attempts at cracking the password? > thanks.
- Next message: Roger Abell: "Re: Dear Microsoft... Rebooting servers id NOT security.."
- Previous message: Peter Foldes: "Re: Can Someone please explain"
- In reply to: mocity: "best practices: builtin administrator account in AD"
- Next in thread: Steven L Umbach: "Re: best practices: builtin administrator account in AD"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|