Re: Remove Administrator Account from Administrators Group



That's what Mathieu chateau was trying to suggest

have you tried the GPO:
Computer configuration
Security Settings
Local policies
Security Options
Accounts: Rename administrator account

That's the GPO setting you need to configure to rename the local
administrator account.

Bye
Gabriele

"Thomas M." wrote:

Thanks for the reply. I have not tried what you suggest, but I thought that
there might be a policy for it somewhere. I was just looking in the wrong
place. It looks like what I need and I'll give it a try.

As for the LAN man hash, is this the policy that you are referring to:

Network security: Do not store LAN Manager hash value on next password
change

--Tom

"Mathieu CHATEAU" <gollum123@xxxxxxx> wrote in message
news:8A4B87C9-9310-42C1-900B-761548A7A750@xxxxxxxxxxxxxxxx
Hello,

have you tried the GPO:
Computer configuration
Security Settings
Local policies
Security Options
Accounts: Rename administrator account

Don't forget to disable Lan man hash, or it will be really easy to break
it with rainbow table

--
Cordialement,
Mathieu CHATEAU
http://lordoftheping.blogspot.com


"Thomas M." <NoEmailReplies@xxxxxxxxxx> wrote in message
news:u7zTcgM6HHA.3716@xxxxxxxxxxxxxxxxxxxxxxx
We are in the process of creating a group policy that will limit user
rights on the desktop. A major element of our group policy is that it
will push down the local Administrators group, which will contain a
domain group for Network Administrators so that we will have
administrator rights to all machines. Currently, the local Administrator
account is a member of the Administrators group that is pushed down by
the group policy. Our security officer would like us to either remove
the local Administrator account from the group policy, or push it down
under a different name. In other words, if you were to logon to a PC
that gets the group policy, and check the local Administrators group, you
would not see the local Administrator account listed as a member, but you
might see an account called something like "SecureDesktop" that would be
the local Administrator account under a different name.

Given that you can't manually remove the local Administrator account from
the local Administrators group (you get a message akin to, "This action
is not allowed for built-in accounts"), I would say that what our
security officer is asking may not be possible. However, I am very new
to group policies and thought that I should seek some expert advice on
whether or not this can be achieved through a group policy.

Is there a way through a group policy to remove the local Administrator
account from the local Administrators group, or to push it down under a
different name?

--Tom





.



Relevant Pages

  • Administrator password during WinXP installation?
    ... password when WinXP Professional boots up to the WinXP ... Professional installation for the Administrator account ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Help - administrator locked out!
    ... a DC the local administrator account 'goes away'. ... pretty sure I should be able to remember the local admin password. ... The Administrator account shouldn't have it's password set to expire ... I'm not knocking your career choice but it's your practices that got ...
    (microsoft.public.windows.server.general)
  • RE: Corrupt Administrator Account?
    ... Thank you for posting in SBS newsgroup. ... Standard SP1 and an Administrator account can not log onto any client ... it will have the administrator privilege on your workstation. ...
    (microsoft.public.windows.server.sbs)
  • Re: Help Please: XP Recovery Console Administrator Password Problem
    ... I think that you should fix the Administrator account problem. ... In the future remember that if you really can't log on to a Windows installation there are other ways around the problem... ... with XP Home being that there is no Group Policy ...
    (microsoft.public.windowsxp.general)
  • Re: Document and settingsAdministrator folder missing
    ... If your computer is working fine, having the Administrator account active on ... Booting into Safe Mode should not be a problem as your other accounts would be ... I have this folder before and I have logged in as administartor when I first ...
    (microsoft.public.windowsxp.general)