RE: Administrator in Domain Admins group

Michael Sturtz <[email protected]> Mon, 31 Jan 2011 10:16:16 -0800
Newsgroups gmane.comp.security.microsoft
Message-ID <CC7184D269417D499C35FDA8F677BD9480FEAC50@itdrenmxm3.na.paccar.com>
The "Built in Administrator" account CAN be deleted however it is strongly =
cautioned against doing this.  One of the reasons is it is the account that=
 is used in safe mode should a disaster occur.   If the built in Administra=
tor account is locked out you can reboot the system in safe mode (by hittin=
g the F8 key at startup) and still logon to the account and fix your system=
.  If you delete or remove the built in administrator account you will be u=
nable to logon to the system.  I would recommend renaming the built in admi=
nistrator account to a different name and then creating a new account named=
 Administrator that is not a member of the Administrators or Domain Adminis=
trators group and is disabled.  This account is a decoy to prevent nuisance=
 attacks on your default administrator account. =20
Michael Sturtz

-----Original Message-----
From: [email protected] [mailto:[email protected]] On=
 Behalf Of Shang Tsung
Sent: Monday, January 31, 2011 7:58 AM
To: [email protected]
Subject: Administrator in Domain Admins group

After an audit, I noticed that in the Domain Admins group of our domain, th=
ere is an account named Administrator. As my engineers told me, this accoun=
t is created by default when you create a new domain and cannot be deleted =
or disabled. Is this true? I am not convinced yet.

We do not like general purpose accounts like this because we lose accountab=
ility. I am pretty sure the password of that account is in the hands of peo=
ple who are not supposed to have it. Each domain admin has his own account =
who is in the Domain Admins group, so there is no need for this Administrat=
or account.

Can we delete it? And if yes, what would be the consequences?

Thanks,
Shang Tsung