Re: Disabling Administrator Acount




"jamestulloch" <james@xxxxxxxxxxxxxxxx> wrote in message
news:1177506635.406767.9780@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
Hello All,

The best practise for securing AD is to disable the administrator
acount. Clearly you will need in advance to have created a sufficient
number of other administrators so that you reduce the chance of
locking yourself out completely.

That's not a best practice. In fact, don't do it.

If you use account lockout (and you should as THIS is a best
practice) then an attack can lock out EVERY account.

Even renaming the admin account is an old recommendation that
no longer is worth the trouble (hackers know the well-known SID
and can come at it that way.)


However, are there other issues that you might run into. Is the
administrator account referenced directly anywhere, on the box, in
the
regsitry or within AD that could cause issues.


I have created a user account with the same group membership as
"administrator" but still occassionally have problems that seem to
point towards permissions issues.


Any thoughts?

Don't do it.

Give the admin account a LONG, COMPLEX password and don't
use it day to day. Write down that password and lock it in a
safe place.


--
Herb Martin, MCSE, MVP
http://www.LearnQuick.Com
(phone on web site)


.



Relevant Pages

  • Re: Administrator Account User is Locked-out
    ... Where you using the built in Administrator account or another account with Admin privileges that you created? ... Good practice is to create at least one other account with admin privileges for day to day activities, set a strong password on the Administrator account and set that aside. ...
    (microsoft.public.windowsxp.general)
  • Re: Office 2003 Standard On Vista
    ... If by that you mean the built-in administrator, then as an off-topic reply, ... Please be aware that it is VERY BAD PRACTICE to use the built-in ... Administrator account on a day-to-day basis and as your only account on the ...
    (microsoft.public.office.setup)
  • Re: UNLOCKING ADMINISTRATOR PASSWORD
    ... > interactive logon. ... > administrator account is such a target and needs a very complex ... Other than using a complex password, is it still advisable to rename the ... "Administrator" account to something else (since it should still retain ...
    (microsoft.public.win2000.security)
  • Re: User Accounts & Logon Issue
    ... adminstrator account and I want to make my user account the default log on ... account which are not accessible in administrator account. ... but you can navigate to the other if you have permission ... It is best practice not to use the Administrtaor account for day to ...
    (microsoft.public.windowsxp.basics)
  • Terminal Services Account - "Administrator" account secure?
    ... a long complex password to my "Administrator" account. ... I am concerned that a hacker may attempt brute forced passwords to log in ...
    (microsoft.public.inetserver.iis.security)