Jump to content

I'm struggling to get the server login details from previous incumbents!!!


Recommended Posts

Posted

I'm taking over the support contract for a primary school, and the previous company doesn't seem to wish to pass on the domain admin username and password. No-one at the school knows these details either! Eventually, the Office manager managed to obtain a password that I have tried (with numerous permutations!) and doesn't work.

So I have called them myself (a bit frosty - to be expected I suppose) and the person I need to speak to will get back to me (yeah right still waiting)

So........

I would be interested to know how others have dealt with similar situations.

I have physical access to the domain controller. What are the SAFE options to reset the administrator password?

I am inclined to name and shame - this is highly unprofessional. Are we allowed to do that on this forum?

Posted

If that is the correct password are you trying to log on with it locally onto the server or using the domain login? As they can be different?

 

eg domain name\administrator is different to computer name\administrator

 

Sorry if it sounds obvious :D

Posted

Ok - is your Anti-Virus or backup provided by your LEA?

 

AV and backup service accounts are normally domain admin accounts. If your LEA is anything like Service Birmingham the default username/password will be the same across the authority.

 

For example if you use Sophos AV provided by your LEA ask them for the default service account credentials (or even look on their support portal). If they need the Head to email them, then ask them.

 

Do you use Ranger? Is there a Ranger account?

 

Normally most networks have at least a couple of service accounts that require domain admin to read/install what is required. This could be a way in, assuming the support company hasn't denied logon to service accounts in GP!

Posted
AV and backup service accounts are normally domain admin accounts.

 

They are not normally domain admin accounts. They should never ever be domain admin accounts, its bad practise. I would be surprised if they do use domain admin accounts.

Posted
They are not normally domain admin accounts. They should never ever be domain admin accounts, its bad practise. I would be surprised if they do use domain admin accounts.

 

What if you're wanting to manage AV and backups of a DC, and these applications require local admin rights? How do you provide this on a DC without making it a Domain admin?

Posted
They are not normally domain admin accounts. They should never ever be domain admin accounts, its bad practise. I would be surprised if they do use domain admin accounts.

 

 

Tell Service Birmingham that. Not only is it their practice, if you spend ages playing around with permissions for their backup account and remove it from domain admins, they put it back and tell you it's unsupported.

Posted
I can't remember the exact bus but watch this, Ten Deadly Sins of Administrators about Windows S…: Ten Deadly Sins of Administrators about Windows Security - YouTube well with watching anyway, I think it's in this video but might be another of hers. There should be something in there you can use.

 

This has worked a treat. I created a WinPE bootable and added the appropriate RAID drivers, and followed the presenters instructions. Its deadly sin number 9 about a third of the way in. Definitely worth watching.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...