RE: local users and groups

From: BDedman (BDedman_at_discussions.microsoft.com)
Date: 07/07/04


Date: Wed, 7 Jul 2004 09:03:02 -0700

It could be that he had made a copy of the Original local Administrator's account. That's your most likely cause. It could also be that he has a user that is in the Account Operators Local Group, giving him access to reset passwords and such.
The hidden account could be any of the ones on the list, just look for ones that don't follow your Naming Convention.
Good Luck with this, i hope my tips helped, even a little bit.

Brandon Dedman
Microsoft Certified Professional
Microsoft Certified Systems Administrator

"administrator" wrote:

> Hi,
>
> we had a user who was an admin of the local machine
> we then made him a power user and reset the admin password
> he has now made himself an admin again and removed dom admins from the admin group
> how was he able to do only being a power user?
> is it possible he has some sort of hidden account? how and where would this be?
>
> Thanks



Relevant Pages

  • Re: Use of credentials with UAC in vista
    ... user's account, from a command prompt with 'run as administrator' privledges, and it failed saying access denied. ... The user's account has power user permissions. ... There is no more Power User on Vista, ... It also appears from reading the above article that it did indeed cache my admin credentials. ...
    (microsoft.public.windows.vista.general)
  • Re: Incoming E-Mail - cant create contact in OU
    ... central admin pool different than the web app. ... that account a little (if the web app is compromised or something, ... So I started with giving the app pool account domain admins permissions then ...
    (microsoft.public.sharepoint.windowsservices)
  • Re: Security Breach in AD! Help!
    ... > about 5 minutes the user was removed from the built in admin group. ... > changed the default domain policy, the default domain controller policy, ... >> auditing of account logon for success and failure and account management ... >> success and failure in Domain Controller Security Policy. ...
    (microsoft.public.win2000.security)
  • Re: We are there--everything is perfect, except: Power User/Adminstrator
    ... > Power User Account and use that most of the time, ... > of one of the administrator accounts to it? ... using (I'm not sure if you'll have to log out then log in as admin to do ...
    (microsoft.public.windowsxp.configuration_manage)
  • Re: cant verify disk
    ... She went to DU, and when she pressed "verify disk", it asked her user ... Disk Utility has required an administrator name and password for certain ... This is clearly a task which requires admin privileges, ... seriously mucked up with her user account settings in the NetInfo ...
    (comp.sys.mac.system)