Windows IT Pro is the leading independent community for IT professionals deploying Microsoft Windows server and client applications and technologies.
  
  
  Advanced Search 


November 10, 2000

Protecting the Administrator Account


RSS
View this exclusive article with VIP access -- click here to join |
See More Security Articles Here | Reprints | Or sign up for our VIP Monthly Pass!

Windows 2000's built-in Administrator account needs special protection against attacks because of several idiosyncrasies that Win2K inherited from Windows NT. Each Win2K Professional workstation and Win2K member server (e.g., not a domain controller—DC) has a local SAM database that always contains at least two user accounts: Administrator and Guest. Both of these accounts are potential targets for intruders, and you can't delete either account. Although Win2K disables the Guest account by default, which reduces the associated risk as long as you keep this account disabled, the Administrator account is different. For example, even though you can specify an account lockout policy for the local system using the Local Security Policy Microsoft Management Console (MMC) snap-in, Win2K ignores this policy for the Administrator account. In other words, you can't lock out the Administrator account no matter how many times you try to log on.

According to Win2K’s Help text, Microsoft made these exceptions so "that you never lock yourself out of the computer by deleting or disabling all the administrative accounts." Although this decision sprang from good intentions for inexperienced or careless users, it leaves serious security administrators who need to harden systems out in the cold. Attackers know that the Administrator account exists; that this account must be enabled; that it is all powerful; and that no matter how long they pound on this account with password guesses, it won’t lock out. . . .


Already a VIP member?
Please log on to view the full article

Why become a VIP member?

VIP-only online access
VIP CD delivered twice a year: offline access to the entire Windows IT Pro article library
Monthly issue of your choice of Windows IT Pro or SQL Server Magazine

Subscribe Now
Reader Comments
I just set up a w2k professional, created two users as the admin, and now i am locked out of the administrator account.. i thought the admin account could never be locked out. Can you help?

Jeff March 11, 2002


I dont know what i have done. I took a work computer home to do work over the weekend and have locked all the accounts out, even the administrator. is there some way that i can access my personal files?

ty August 03, 2003


i'm a complete numpty and i've locked myself out of my house

Anonymous User October 26, 2004


The advice to create a local administrator account may be fine for a small business, but for a large corp it is not pratical. How does one protect the local admin account when the network is not available and a tech needs to get in?

Anonymous User February 04, 2005


You must be a registered user or online subscriber to comment on this article. Please log on before posting a comment. Are you a new visitor? Register now




Top Viewed ArticlesView all articles
Battery Life Issues Almost Certainly Not Windows 7's Fault

While Microsoft is still investigating a notebook battery life issue that was supposedly caused by Windows 7, some interesting trends have emerged. ...

Getting your iPhone to Sync with Exchange 2003

Follow these steps to use an iPhone with Exchange. ...

Command Prompt Tricks

One reader shares his tip for setting up the command prompt to reflect a remote path. ...


Security Whitepapers Reducing the Costs and Risks of Branch Office Data Protection

Solving Desktop Management Challenges in Healthcare

Solving Desktop Management Challenges in Education

Related Events The Increasing Threat of Financially Motivated Data Theft

Introduction to Identity Lifecycle Manager "2"

Configuration Manager SP1 and R2 Overview

Check out our list of Free Email Newsletters!

Security eBooks Spam Fighting and Email Security for the 21st Century

Understanding and Leveraging Code Signing Technologies

A Guide to Windows Certification and Public Keys

Related Security Resources Introducing Left-Brain.com, the online IT bookstore
Looking for books, CDs, toolkits, eBooks? Prime your mind at Left-Brain.com

Discover Windows IT Pro eLearning Series!
Clear & detailed technical information and helpful how-to's, all in our trademark no-nonsense format


Windows IT Pro Home Register FAQ for Windows WinInfo News
Europe Edition About Us Contact Us/Customer Service Media Kit Affiliates / Licensing  
SQL Server Magazine Office & SharePoint Pro DevProConnections IT Job Hound
Left-Brain.com Technology Resource Directory asp.netPRO ITTV Windows SuperSite 
 
 Windows IT Pro is a Division of Penton Media Inc.
 © 2010 Penton Media, Inc. Terms of Use | Privacy Statement