Real Geek Forums  

Go Back   Real Geek Forums > Archives > Operating Systems > Windows Vista > Windows Vista Security

Notices

Reply

Built-in Administrator acct. for Domain be password never expires?

 

LinkBack Thread Tools Display Modes
Old 10-02-2006, 07:01 PM   #1 (permalink)
Default Built-in Administrator acct. for Domain be password never expires?

Are there any risks associated with an expired built-in Administrator
password? I've been googling but can't seem to quite get results that speak
to this issue.


Guest
 
Posts: n/a
Reply With Quote  
Old 10-02-2006, 08:19 PM   #2 (permalink)
Default Re: Built-in Administrator acct. for Domain be password never expires?

In article <#rMg9Ul5GHA.4616@TK2MSFTNGP05.phx.gbl>, <-> says...
Quote:
> Are there any risks associated with an expired built-in Administrator
> password? I've been googling but can't seem to quite get results that speak
> to this issue.
>
>
>
The risk is that you cannot log in with the account once the password has expired without
resetting it. If an attacker is able to determine the original password, due to poor password
implementation, they could change the password from under you.
Brian
Brian Komar [MVP]
Guest
 
Posts: n/a
Reply With Quote  
Old 10-02-2006, 10:43 PM   #3 (permalink)
Default Re: Built-in Administrator acct. for Domain be password never expires?

So is it better practice to have it expire, or to never expire?


"Brian Komar [MVP]" <bkomar@nospam.identit.ca> wrote in message
news:MPG.1f8b30636e4cb7849896c9@msnews.microsoft.c om...
Quote:
> In article <#rMg9Ul5GHA.4616@TK2MSFTNGP05.phx.gbl>, <-> says...
Quote:
>> Are there any risks associated with an expired built-in Administrator
>> password? I've been googling but can't seem to quite get results that
>> speak
>> to this issue.
>>
>>
>>
> The risk is that you cannot log in with the account once the password has
> expired without
> resetting it. If an attacker is able to determine the original password,
> due to poor password
> implementation, they could change the password from under you.
> Brian

Guest
 
Posts: n/a
Reply With Quote  
Old 10-03-2006, 01:21 AM   #4 (permalink)
Default Re: Built-in Administrator acct. for Domain be password never expires?

In news:%23rMg9Ul5GHA.4616@TK2MSFTNGP05.phx.gbl,
- <-> typed:
Quote:
> Are there any risks associated with an expired built-in Administrator
> password? I've been googling but can't seem to quite get results
> that speak to this issue.
You can't make the built-in domain admin account password expire, to the
best of my knowlege.

Really, nobody should be using that account for their admin work anyway, nor
should it be used to run system services. Just set it up with a good,
complex password, write that down on a piece of paper and put it in a sealed
envelope, and give that to the company owner so that he or she can fire the
entire IT department without getting screwed over. Any techs working on the
network should have two accounts - one for daily use (user only), and
another that has the delegated domain permissions they need to do their
jobs. Complex passwords & regular changes should be forced.

This is an "ideal world" setup, but hey, we can strive for that, right?


Lanwench [MVP - Exchange]
Guest
 
Posts: n/a
Reply With Quote  
Old 10-03-2006, 04:07 AM   #5 (permalink)
Default Re: Built-in Administrator acct. for Domain be password never expires?

I have to go with Lanwench on this one. Complexity is good. Keep it in a safe. Break glass in
case of emergency
Brian

In article <OwTGyQn5GHA.2044@TK2MSFTNGP02.phx.gbl>, <-> says...
Quote:
> So is it better practice to have it expire, or to never expire?
>
>
> "Brian Komar [MVP]" <bkomar@nospam.identit.ca> wrote in message
> news:MPG.1f8b30636e4cb7849896c9@msnews.microsoft.c om...
Quote:
> > In article <#rMg9Ul5GHA.4616@TK2MSFTNGP05.phx.gbl>, <-> says...
Quote:
> >> Are there any risks associated with an expired built-in Administrator
> >> password? I've been googling but can't seem to quite get results that
> >> speak
> >> to this issue.
> >>
> >>
> >>
> > The risk is that you cannot log in with the account once the password has
> > expired without
> > resetting it. If an attacker is able to determine the original password,
> > due to poor password
> > implementation, they could change the password from under you.
> > Brian
>
>
>
Brian Komar [MVP]
Guest
 
Posts: n/a
Reply With Quote  
Reply

Tags
None

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads

Thread Thread Starter Forum Replies Last Post
Vista wants a network administrator password now i'm connected to the domain, everything's locked! Guest Windows Vista 0 03-07-2008 10:45 AM
Warning! No Password set for built-in administrator account chrisgruntled Windows Vista Administration 4 07-06-2006 01:48 AM
Logon to built-in administrator account (Win Vista) Tim R. Windows Vista Administration 2 06-22-2006 06:09 PM
What happens to the built-in Administrator Account Deborggraeve Randy Windows Vista Security 6 03-14-2006 09:14 AM
password expires Gianluca Facca Windows XP Embedded 2 08-26-2003 10:33 AM


All times are GMT. The time now is 06:51 AM.


Powered by vBulletin® Version 3.7.1
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Copyright © 2005 - 2007 RealGeek.com. All rights reserved.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90