RE: Administrator in Domain Admins group
Michael Sturtz <[email protected]> Mon, 31 Jan 2011 10:16:16 -0800
| Newsgroups | gmane.comp.security.microsoft |
|---|---|
| Message-ID | <CC7184D269417D499C35FDA8F677BD9480FEAC50@itdrenmxm3.na.paccar.com> |
The "Built in Administrator" account CAN be deleted however it is strongly = cautioned against doing this. One of the reasons is it is the account that= is used in safe mode should a disaster occur. If the built in Administra= tor account is locked out you can reboot the system in safe mode (by hittin= g the F8 key at startup) and still logon to the account and fix your system= . If you delete or remove the built in administrator account you will be u= nable to logon to the system. I would recommend renaming the built in admi= nistrator account to a different name and then creating a new account named= Administrator that is not a member of the Administrators or Domain Adminis= trators group and is disabled. This account is a decoy to prevent nuisance= attacks on your default administrator account. =20 Michael Sturtz -----Original Message----- From: [email protected] [mailto:[email protected]] On= Behalf Of Shang Tsung Sent: Monday, January 31, 2011 7:58 AM To: [email protected] Subject: Administrator in Domain Admins group After an audit, I noticed that in the Domain Admins group of our domain, th= ere is an account named Administrator. As my engineers told me, this accoun= t is created by default when you create a new domain and cannot be deleted = or disabled. Is this true? I am not convinced yet. We do not like general purpose accounts like this because we lose accountab= ility. I am pretty sure the password of that account is in the hands of peo= ple who are not supposed to have it. Each domain admin has his own account = who is in the Domain Admins group, so there is no need for this Administrat= or account. Can we delete it? And if yes, what would be the consequences? Thanks, Shang Tsung