A Windows Vista forum. Vista Banter

Welcome to Vista Banter.

You are currently viewing our boards as a guest which gives you limited access to view most discussions, articles and access our other FREE features. By joining our free community you will have access to ask questions and reply to others posts, upload your own photos and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact contact support.

Go Back   Home » Vista Banter forum » Microsoft Windows Vista » Security and Windows Vista
Site Map Home Register Authors List Search Today's Posts Mark Forums Read Web Partners

Security and Windows Vista A forum for discussion on security issues with Windows Vista. (microsoft.public.windows.vista.security)

Built-in Administrator acct. for Domain be password never expires?



 
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old October 2nd 06, 07:01 PM posted to microsoft.public.security,microsoft.public.win2000.security,microsoft.public.windows.server.security,microsoft.public.windows.vista.security
Guest
 
Posts: n/a
Default Built-in Administrator acct. for Domain be password never expires?

Are there any risks associated with an expired built-in Administrator
password? I've been googling but can't seem to quite get results that speak
to this issue.


  #2 (permalink)  
Old October 2nd 06, 08:19 PM posted to microsoft.public.security,microsoft.public.win2000.security,microsoft.public.windows.server.security,microsoft.public.windows.vista.security
Brian Komar [MVP]
external usenet poster
 
Posts: 22
Default Built-in Administrator acct. for Domain be password never expires?

In article , - says...
Are there any risks associated with an expired built-in Administrator
password? I've been googling but can't seem to quite get results that speak
to this issue.



The risk is that you cannot log in with the account once the password has expired without
resetting it. If an attacker is able to determine the original password, due to poor password
implementation, they could change the password from under you.
Brian
  #3 (permalink)  
Old October 2nd 06, 10:43 PM posted to microsoft.public.security,microsoft.public.win2000.security,microsoft.public.windows.server.security,microsoft.public.windows.vista.security
Guest
 
Posts: n/a
Default Built-in Administrator acct. for Domain be password never expires?

So is it better practice to have it expire, or to never expire?


"Brian Komar [MVP]" wrote in message
om...
In article , - says...
Are there any risks associated with an expired built-in Administrator
password? I've been googling but can't seem to quite get results that
speak
to this issue.



The risk is that you cannot log in with the account once the password has
expired without
resetting it. If an attacker is able to determine the original password,
due to poor password
implementation, they could change the password from under you.
Brian



  #4 (permalink)  
Old October 3rd 06, 01:21 AM posted to microsoft.public.security,microsoft.public.win2000.security,microsoft.public.windows.server.security,microsoft.public.windows.vista.security
Lanwench [MVP - Exchange]
external usenet poster
 
Posts: 3
Default Built-in Administrator acct. for Domain be password never expires?

In ,
- - typed:
Are there any risks associated with an expired built-in Administrator
password? I've been googling but can't seem to quite get results
that speak to this issue.


You can't make the built-in domain admin account password expire, to the
best of my knowlege.

Really, nobody should be using that account for their admin work anyway, nor
should it be used to run system services. Just set it up with a good,
complex password, write that down on a piece of paper and put it in a sealed
envelope, and give that to the company owner so that he or she can fire the
entire IT department without getting screwed over. Any techs working on the
network should have two accounts - one for daily use (user only), and
another that has the delegated domain permissions they need to do their
jobs. Complex passwords & regular changes should be forced.

This is an "ideal world" setup, but hey, we can strive for that, right?


  #5 (permalink)  
Old October 3rd 06, 04:07 AM posted to microsoft.public.security,microsoft.public.win2000.security,microsoft.public.windows.server.security,microsoft.public.windows.vista.security
Brian Komar [MVP]
external usenet poster
 
Posts: 22
Default Built-in Administrator acct. for Domain be password never expires?

I have to go with Lanwench on this one. Complexity is good. Keep it in a safe. Break glass in
case of emergency
Brian

In article , - says...
So is it better practice to have it expire, or to never expire?


"Brian Komar [MVP]" wrote in message
om...
In article , - says...
Are there any risks associated with an expired built-in Administrator
password? I've been googling but can't seem to quite get results that
speak
to this issue.



The risk is that you cannot log in with the account once the password has
expired without
resetting it. If an attacker is able to determine the original password,
due to poor password
implementation, they could change the password from under you.
Brian




 




Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT. The time now is 06:43 PM.


Powered by vBulletin® Version 3.6.4
Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.Search Engine Optimization by vBSEO 3.0.0 RC6
Copyright ©2004-2024 Vista Banter.
The comments are property of their posters.