Re: Change local admin passwords on all domain PCs
- From: "John Policelli [MVP-DS]" <JohnPolicelliMVPDS@xxxxxxxxxxxxxxxxxxxxxxxxx>
- Date: Sun, 9 Nov 2008 12:09:05 -0500
Again, another desktop deployment question...
I have seen companies assign the local Administrator password during the build process. They also have a domain user account, which is added to the local Administrators group, that has the necessary permissions to join the PC to the domain and perform post-installation tasks.
--
John Policelli,
This posting is provided "AS IS" with no warranties and confers no rights!
http://johnpolicelli.wordpress.com/
----
"Meinolf Weber" <meiweb(nospam)@gmx.de> wrote in message news:ff16fb66d5f38cb0ff6410cdc60@xxxxxxxxxxxxxxxxxxxxxxx
Hello John Policelli [MVP-DS],
How do you handle it with saving the local admin password, when you have to logon locally without the domain? Do you have all of them listed in your office?
Best regards
Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and confers no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm
Guy,
The requirements you set up now are different than those you included
in your initial post.
My recommendation to avoid using the same password for the local
Administrator is still valid though. It sounds like you need to look
into some of the desktop deployment (MS and non-MS based) solutions
that are on the market. These deal with your requirements.
"Guy Pardoe" <guy@xxxxxxxxxxxxxxxx> wrote in message
news:O4sZ8xAQJHA.3936@xxxxxxxxxxxxxxxxxxxxxxx
Hmmmmm... OK then, let's back up a step.
When a new machine is ordered and comes out of the box, IT has to
join it to the domain, do some configuration and load up some
software for the intended employee. We can't use the intended
employee's account because they don't have admin privileges and can't
install most software.
What account do you use for these "pre-deployment" tasks. If you use
domain admin, then that is cached to the local PC with a risk of also
being cracked. That would be worse.
Taking your point of security, how do you manage this?
Guy
John Policelli [MVP-DS] wrote:
So in other words, if someone cracks the local admin password on one
of your computers, you're ok with them then having the local admin
password to all computers? You may want to rethink your strategy.
Never choose convenience over security.
.
- Follow-Ups:
- Re: Change local admin passwords on all domain PCs
- From: Guy Pardoe
- Re: Change local admin passwords on all domain PCs
- References:
- Re: Change local admin passwords on all domain PCs
- From: John Policelli [MVP-DS]
- Re: Change local admin passwords on all domain PCs
- From: Meinolf Weber
- Re: Change local admin passwords on all domain PCs
- Prev by Date: 2003 R2 DCs and 2008 member servers
- Next by Date: Re: "Access Denied" message when adding member server in existing
- Previous by thread: Re: Change local admin passwords on all domain PCs
- Next by thread: Re: Change local admin passwords on all domain PCs
- Index(es):
Relevant Pages
|
Loading