Re: Local Administrator Account




"John" <John@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:4FA8B2F0-F28D-492C-8DD6-C5C64857BD66@xxxxxxxxxxxxxxxx
I have a Windows 2003 Active Directory environment. I have XP workstations
and member servers with the local administrator account password set the
same. I logged into the XP workstation as the local administrator. Then
I
was able to access all the administrative shares of the other workstations
and member servers that have the same password. I would be able to unc
path
to \\server\c$ without a domain authenication prompt. I remember this was
an
issue in the NT domain days when you could log on to other domains with if
the administrator account and passwords were the same. I checked another
Windows 2003 AD as well as a 2000 AD and it still happened. Any ideas why
and how to stop it?

If I understand the "why" part of your question, I think the MS
answer would be that it is by design.
How to stop it?
Do not use the same password everywhere, or do not use the
same account everywhere, or preferable do neither.
As you outline, loss of the credentials on one machine could
spread like wildfire throughout your infrastructure with things
as you have them, so one obviously should not have them so.
Give the builtin Administrator account (however renamed if
renamed) a long, strong, complex passphrase that is not the
same as elsewhere. Use your domain accounts for uniform
access if/when/as required.

Roger


.



Relevant Pages

  • Re: Changing workstation Admin password through AD
    ... bouncing every member server and workstation monthly is not practical. ... GPO/startup script method... ... Windows Server MVP - Directory Services ... Change the password to the Administrator account ...
    (microsoft.public.win2000.active_directory)
  • Re: How to deny Access at Clients?
    ... Thank you for using Microsofts Small Business Server newsgroups. ... understand that you want to lock a workstation down so that only two people ... It is also necessary to be very careful setting Deny ... domain Administrator account (the built in Administrator account on the ...
    (microsoft.public.windows.server.sbs)
  • Re: Changing workstation Admin password through AD
    ... Anyone who can get to power user or admin level on a workstation will have a path to get that batch file and anyone with physical access to a machine can get admin regardless of what their "official" access level is. ... Change the password to the Administrator account ... I know how to rename the administrator's account, but how can I do the ...
    (microsoft.public.win2000.active_directory)
  • Riprep of WinXP SP2 disables local administrator
    ... it installs with the local administrator account ... I can setup a WinXP SP2 workstation with the local ... I build a workstation from that RIS image, the local administrator account ... The same problem does not happen when creating a RIS image from a WinXP SP1 ...
    (microsoft.public.windowsxp.setup_deployment)
  • Local policy does not permit you to logon interactively
    ... I had a Windows 2000 Workstation ... Windows 2000 server and I wasn't the person who configured it initially. ... not even the local administrator account (which had been working before ... I REALLY don't want to reload this system and I need to find ...
    (microsoft.public.win2000.networking)