A Windows Vista forum. Vista Banter

Welcome to Vista Banter.

You are currently viewing our boards as a guest which gives you limited access to view most discussions, articles and access our other FREE features. By joining our free community you will have access to ask questions and reply to others posts, upload your own photos and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact contact support.

Go Back   Home » Vista Banter forum » Microsoft Windows Vista » Security and Windows Vista
Site Map Home Register Authors List Search Today's Posts Mark Forums Read Web Partners

Security and Windows Vista A forum for discussion on security issues with Windows Vista. (microsoft.public.windows.vista.security)

Encrypting Administrator's profile



 
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old January 9th 09, 09:45 AM posted to microsoft.public.windows.server.security,microsoft.public.windows.vista.security,microsoft.public.windowsxp.security_admin
Kirsten[_2_]
external usenet poster
 
Posts: 2
Default Encrypting Administrator's profile

Is there any way to encrypt (EFS or similar) the entire administrator's
profile folder (C:\Documents and Settings\Administrator) so as to prevent a
user from login in to the computer if he changes the password with a dos
utility? (CIA Commander for example).

There's no point in having domain policies if the user can login as the
administrator and do whetever he wants with the computer!

What else do you suggest? (please don't say "put a bios password" or "forbid
physical access to the computer")

Thanks a lot!



  #2 (permalink)  
Old January 9th 09, 02:24 PM posted to microsoft.public.windows.server.security,microsoft.public.windows.vista.security,microsoft.public.windowsxp.security_admin
Shenan Stanley
external usenet poster
 
Posts: 286
Default Encrypting Administrator's profile

Kirsten wrote:
Is there any way to encrypt (EFS or similar) the entire
administrator's profile folder (C:\Documents and
Settings\Administrator) so as to prevent a user from login in to
the computer if he changes the password with a dos utility? (CIA
Commander for example).
There's no point in having domain policies if the user can login as
the administrator and do whetever he wants with the computer!

What else do you suggest? (please don't say "put a bios password"
or "forbid physical access to the computer")


Why is this user able to logon as an administrative level account in the
first place?

--
Shenan Stanley
MS-MVP
--
How To Ask Questions The Smart Way
http://www.catb.org/~esr/faqs/smart-questions.html


  #3 (permalink)  
Old January 9th 09, 02:53 PM posted to microsoft.public.windows.server.security,microsoft.public.windows.vista.security,microsoft.public.windowsxp.security_admin
Kirsten[_2_]
external usenet poster
 
Posts: 2
Default Encrypting Administrator's profile

He's not, but there are several utilities that easily disable the
administrator account.

"Shenan Stanley" wrote in message
...
Kirsten wrote:
Is there any way to encrypt (EFS or similar) the entire
administrator's profile folder (C:\Documents and
Settings\Administrator) so as to prevent a user from login in to
the computer if he changes the password with a dos utility? (CIA
Commander for example).
There's no point in having domain policies if the user can login as
the administrator and do whetever he wants with the computer!

What else do you suggest? (please don't say "put a bios password"
or "forbid physical access to the computer")


Why is this user able to logon as an administrative level account in the
first place?

--
Shenan Stanley
MS-MVP
--
How To Ask Questions The Smart Way
http://www.catb.org/~esr/faqs/smart-questions.html



  #4 (permalink)  
Old January 9th 09, 03:04 PM posted to microsoft.public.windows.server.security,microsoft.public.windows.vista.security,microsoft.public.windowsxp.security_admin
Gordon[_5_]
external usenet poster
 
Posts: 1,032
Default Encrypting Administrator's profile

Kirsten wrote:
He's not, but there are several utilities that easily disable the
administrator account.


Sounds like some discipline is in order. If this is a workplace, make it
a sackable offence to install or use any software not authorised by the
company. If a home environment, just deny physically, access to the
machine until the user learns to respect computer security.


--
Asking a question?
Please tell us the version of the application you are asking about,
your OS, Service Pack level
and the FULL contents of any error message(s)
  #5 (permalink)  
Old January 9th 09, 03:37 PM posted to microsoft.public.windows.server.security,microsoft.public.windows.vista.security,microsoft.public.windowsxp.security_admin
Shenan Stanley
external usenet poster
 
Posts: 286
Default Encrypting Administrator's profile

Kirsten wrote:
Is there any way to encrypt (EFS or similar) the entire
administrator's profile folder (C:\Documents and
Settings\Administrator) so as to prevent a user from login in to
the computer if he changes the password with a dos utility? (CIA
Commander for example).
There's no point in having domain policies if the user can login as
the administrator and do whetever he wants with the computer!

What else do you suggest? (please don't say "put a bios password"
or "forbid physical access to the computer")


Shenan Stanley wrote:
Why is this user able to logon as an administrative level account
in the first place?


Kirsten wrote:
He's not, but there are several utilities that easily disable the
administrator account.


Did you mean 'disable' or 'allow them to use' the administrator account?

You didn't want to hear it because you know it's true... "Physical access,
time and a little knowledge means anyone who sits at the machine basically
can own it..."

Are you protecting what's in the administrator account (should be much of
nothing) or is it you just don't want them using the account?

If the latter - your battle is lost before it was started. Encrypt all you
want - physical access can give the user another/the same administrative
account with a little effort and a few tools and time. Maybe not so much
the data in the profile - but there should be nothing in (files, etc) the
actual built-in administrator's account of importance anyway, IMO.

I think you need to divulge what it is you hope to accomplish in order to
better narrow the possible answers. What is the actual problem and need?

--
Shenan Stanley
MS-MVP
--
How To Ask Questions The Smart Way
http://www.catb.org/~esr/faqs/smart-questions.html


  #6 (permalink)  
Old January 14th 09, 01:38 AM posted to microsoft.public.windows.server.security,microsoft.public.windows.vista.security,microsoft.public.windowsxp.security_admin
Mel K.
external usenet poster
 
Posts: 4
Default Encrypting Administrator's profile

You can use a full disk encryption product to encrypt the entire hard drive.
FDE will prevent offline access to the hard drive, meaning you would not be
able to boot the computer into another OS and access the drive. Windows
Vista with BitLocker should do the trick. Vista SP1 made some improvements
to BitLocker.

--
Mel K.
MCSA: M

"Kirsten" wrote in message
...
Is there any way to encrypt (EFS or similar) the entire administrator's
profile folder (C:\Documents and Settings\Administrator) so as to prevent
a
user from login in to the computer if he changes the password with a dos
utility? (CIA Commander for example).

There's no point in having domain policies if the user can login as the
administrator and do whetever he wants with the computer!

What else do you suggest? (please don't say "put a bios password" or
"forbid
physical access to the computer")

Thanks a lot!





  #7 (permalink)  
Old March 27th 10, 12:01 AM
ITgreybeard ITgreybeard is offline
Junior Member
 
First recorded activity by VistaBanter: Mar 2010
Posts: 1
Question

I need to encrypt my personal (admin) profile this very weekend, so that I can send my laptop in for service. Lenovo Repair requests unfettered access to an admin account, a separate one of which I have newly created. But I wish to keep my existing data, including online account passwords stored by browsers, private.

I've backed up the disk, by the way, in its entirety, so that if the laptop comes back to me with a clean slate, I can restore. But I would prefer to not wipe the internal disk clean if it is not needed.

This would seem to be a case that requires profile encryption of some sort, as complete access to the machine is given to a third party.
 




Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT. The time now is 12:18 PM.


Powered by vBulletin® Version 3.6.4
Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.Search Engine Optimization by vBSEO 3.0.0 RC6
Copyright ©2004-2024 Vista Banter.
The comments are property of their posters.