Jump to content

Recommended Posts

Posted

Can anyone tell me the current 'best practice' for the domain Administrator account?

 

I've found this info, however not sure how valid it is.

 

Microsoft Best Practices found on TechNet and MS Press' "Securing Windows Server 2008 R2"

 

1. Don't rename it.

 

You'll waste your effort and (for backward compatibility) if you have any apps/services on your network that require the Admin account to function, they will break.

 

2. Disable the BUILTIN\Administrator.

 

Renaming the account to create a honey pot for attackers is an outdated practice. Any cracker good enough to get this far into your network knows this ploy already. The cracker will just look for the SID ending in -500.

 

3. Create an account with a non-descript name and give it admin rights.

 

That is, name the account "JohnBlack" or "BettyClark". Do not name the account something like Superman, Root, Skywalker, or anything with Admin or ADM in it like testadm or LocalAdmin. Programs that still look for the Admin account by name have evolved enough to check for these names too.

 

4. After you've created the account in step 3, NEVER USE IT!

 

You can't audit Admin access, if you're using it as a regular account (aside from all the other reasons not to use it).

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...