Click here to get back home

Administrator account

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
Administrator account Jeff 07-06-2007
Posted by Jeff on July 6, 2007, 12:43 pm
Please log in for more thread options
Due to turnover in our IT shop we are trying to tighten up security. The
first order of business is to do something with out Administrator account.
The Administrator account was renamed a long time ago to a name within the
naming scheme of the rest of the users. Since all of the people who left our
shop know this account, what is the best way to change this? Should I rename
the account and give it a new password, or should I copy the account. My
concern is that if I rename the account I will cause problems for any server
applications that are relying on it. What is recommended in this scenario?

Also, I want to change the username and password for the local admin account
throughout the domain. Procedure for this please.



Posted by Dave on July 6, 2007, 1:26 pm
Please log in for more thread options

> Due to turnover in our IT shop we are trying to tighten up security. The
> first order of business is to do something with out Administrator account.
> The Administrator account was renamed a long time ago to a name within the
> naming scheme of the rest of the users. Since all of the people who left
> our shop know this account, what is the best way to change this? Should I
> rename the account and give it a new password, or should I copy the
> account. My concern is that if I rename the account I will cause problems
> for any server applications that are relying on it. What is recommended in
> this scenario?
>
> Also, I want to change the username and password for the local admin
> account throughout the domain. Procedure for this please.
>

no server app should rely on the built in Administrator account. you should
rename it, give it a new strong password, then create a new more limited
account to use for apps that need to login on the server. You should also
go through and clean out any old accounts that may not be needed, change the
passwords on any that shouldn't be used by users, etc. If any of the old
administrators left under unfriendly terms you should also check for ports
that are open that shouldn't be, apps running that you don't recognize, do a
good scan for viruses and trojans, and do a full backup asap just in case
one of them gets back in and tries to wipe out something important.





Posted by Special Access on July 6, 2007, 4:41 pm
Please log in for more thread options
On Fri, 6 Jul 2007 10:43:15 -0600, "Jeff"

>Due to turnover in our IT shop we are trying to tighten up security. The
>first order of business is to do something with out Administrator account.
>The Administrator account was renamed a long time ago to a name within the
>naming scheme of the rest of the users. Since all of the people who left our
>shop know this account, what is the best way to change this? Should I rename
>the account and give it a new password, or should I copy the account. My
>concern is that if I rename the account I will cause problems for any server
>applications that are relying on it. What is recommended in this scenario?
>
>Also, I want to change the username and password for the local admin account
>throughout the domain. Procedure for this please.
>

IIRC, renaming the account keeps the SID the same, which is what
security and other access are based on. Renaming is much better than
creating new... With that said, your IT security may say renaming an
account is a bad thing (ours did). Either way, new password is
definately in store (but you already knew that). IF the account is
being used for services, you may run into trouble once you change the
password though.

I seem to remember someone saying you could change the password for
the local admin account using GPO somehow... wish I could remember.
But you might search for it and find some relevant articles from this
NG about it as it wasn't that long ago (couple weeks at most)

Mike

Posted by Steve Riley [MSFT] on July 6, 2007, 6:54 pm
Please log in for more thread options
Rename it back to "Administrator" and set a long passphrase on it.

Changing account names is just security theater. Names are intended to be
public, there is no mechanism in place to prevent discovery of names. So
don't treat such elements as secrets. The secret in a set of credentials is
the password.

See my article for more information on the distinction between identity and
authentication:
http://www.microsoft.com/technet/community/columns/secmgmt/sm0206.mspx

Steve Riley
steve.riley@microsoft.com
http://blogs.technet.com/steriley


> Due to turnover in our IT shop we are trying to tighten up security. The
> first order of business is to do something with out Administrator account.
> The Administrator account was renamed a long time ago to a name within the
> naming scheme of the rest of the users. Since all of the people who left
> our shop know this account, what is the best way to change this? Should I
> rename the account and give it a new password, or should I copy the
> account. My concern is that if I rename the account I will cause problems
> for any server applications that are relying on it. What is recommended in
> this scenario?
>
> Also, I want to change the username and password for the local admin
> account throughout the domain. Procedure for this please.
>

Similar ThreadsPosted
Main Administrator account doesn't have Administrator groups right March 1, 2006, 2:35 pm
Administrator account locking out April 1, 2006, 9:22 am
Local Administrator Account April 17, 2007, 7:28 pm
Returning Administrator Account to 'default' - how to? September 12, 2005, 10:30 am
Local Administrator as service log on account January 11, 2006, 3:51 am
GPO not implementing rename of Administrator Account April 27, 2006, 5:19 am
Disable or rename administrator account September 1, 2006, 3:32 pm
Changing the Administrator account username for security? June 15, 2005, 10:20 am
Administrator account disabled but still get "incorrect password" errors in Event log May 4, 2008, 2:11 pm
Administrator account disabled but still get "incorrect password" errors in Event log May 4, 2008, 2:12 pm

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap