ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    Is it possibe to remove local admin on Windows Server?

    Scheduled Pinned Locked Moved IT Discussion
    15 Posts 6 Posters 607 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • GreyG
      Grey
      last edited by

      A better solution: https://www.microsoft.com/en-us/download/details.aspx?id=46899

      WLS-ITGuyW 1 Reply Last reply Reply Quote 2
      • WLS-ITGuyW
        WLS-ITGuy @Grey
        last edited by

        @Grey said in Is it possibe to remove local admin on Windows Server?:

        A better solution: https://www.microsoft.com/en-us/download/details.aspx?id=46899

        Definitely a better option.

        1 1 Reply Last reply Reply Quote 0
        • 1
          1337 @WLS-ITGuy
          last edited by

          @WLS-ITGuy said in Is it possibe to remove local admin on Windows Server?:

          @Grey said in Is it possibe to remove local admin on Windows Server?:

          A better solution: https://www.microsoft.com/en-us/download/details.aspx?id=46899

          Definitely a better option.

          Ah, so it sets a unique password for local admin on every server and saves those password in the AD so people can find out what the password is?

          GreyG 1 Reply Last reply Reply Quote 0
          • dbeatoD
            dbeato
            last edited by

            @Pete-S said in Is it possibe to remove local admin on Windows Server?:

            ve the local admin account on Windows Server that belongs to a domain? Or prevent logins.
            Or is always possible to login as local admin (if you know the name/passwd)?

            I wouldn't disable the local admin of a server, it would come handy if you need to restore stuff or remove and add from the domain. LAPS works but beware 🙂

            pmonchoP 1 Reply Last reply Reply Quote 1
            • pmonchoP
              pmoncho @dbeato
              last edited by

              @dbeato said in Is it possibe to remove local admin on Windows Server?:

              @Pete-S said in Is it possibe to remove local admin on Windows Server?:

              ve the local admin account on Windows Server that belongs to a domain? Or prevent logins.
              Or is always possible to login as local admin (if you know the name/passwd)?

              I wouldn't disable the local admin of a server, it would come handy if you need to restore stuff or remove and add from the domain. LAPS works but beware 🙂

              I agree with @dbeato. When sh$% hits the fan with the server, no networking or no cached credentials, you will long for a local admin account.

              I do disable the Administrator account after creating my own local admin with 20+ char strong password. Less worries on both the security and DR front.

              GreyG 1 Reply Last reply Reply Quote 1
              • GreyG
                Grey @1337
                last edited by

                @Pete-S said in Is it possibe to remove local admin on Windows Server?:

                @WLS-ITGuy said in Is it possibe to remove local admin on Windows Server?:

                @Grey said in Is it possibe to remove local admin on Windows Server?:

                A better solution: https://www.microsoft.com/en-us/download/details.aspx?id=46899

                Definitely a better option.

                Ah, so it sets a unique password for local admin on every server and saves those password in the AD so people can find out what the password is?

                Correct.

                1 Reply Last reply Reply Quote 0
                • GreyG
                  Grey @pmoncho
                  last edited by

                  @pmoncho said in Is it possibe to remove local admin on Windows Server?:

                  @dbeato said in Is it possibe to remove local admin on Windows Server?:

                  @Pete-S said in Is it possibe to remove local admin on Windows Server?:

                  ve the local admin account on Windows Server that belongs to a domain? Or prevent logins.
                  Or is always possible to login as local admin (if you know the name/passwd)?

                  I wouldn't disable the local admin of a server, it would come handy if you need to restore stuff or remove and add from the domain. LAPS works but beware 🙂

                  I agree with @dbeato. When sh$% hits the fan with the server, no networking or no cached credentials, you will long for a local admin account.

                  I do disable the Administrator account after creating my own local admin with 20+ char strong password. Less worries on both the security and DR front.

                  Yes, but if you have physical or kvm access, even virtual, you can use linux ntpass to turn on the admin account and reset the password. This would be the last resort if you really lost the admin access, which is rare.

                  dbeatoD 1 Reply Last reply Reply Quote 0
                  • dbeatoD
                    dbeato @Grey
                    last edited by

                    @Grey said in Is it possibe to remove local admin on Windows Server?:

                    @pmoncho said in Is it possibe to remove local admin on Windows Server?:

                    @dbeato said in Is it possibe to remove local admin on Windows Server?:

                    @Pete-S said in Is it possibe to remove local admin on Windows Server?:

                    ve the local admin account on Windows Server that belongs to a domain? Or prevent logins.
                    Or is always possible to login as local admin (if you know the name/passwd)?

                    I wouldn't disable the local admin of a server, it would come handy if you need to restore stuff or remove and add from the domain. LAPS works but beware 🙂

                    I agree with @dbeato. When sh$% hits the fan with the server, no networking or no cached credentials, you will long for a local admin account.

                    I do disable the Administrator account after creating my own local admin with 20+ char strong password. Less worries on both the security and DR front.

                    Yes, but if you have physical or kvm access, even virtual, you can use linux ntpass to turn on the admin account and reset the password. This would be the last resort if you really lost the admin access, which is rare.

                    Not since UEFI... At least it doesn't work with Windows 10 and subsequent kernels.

                    GreyG 1 Reply Last reply Reply Quote 1
                    • GreyG
                      Grey @dbeato
                      last edited by

                      @dbeato said in Is it possibe to remove local admin on Windows Server?:

                      @Grey said in Is it possibe to remove local admin on Windows Server?:

                      @pmoncho said in Is it possibe to remove local admin on Windows Server?:

                      @dbeato said in Is it possibe to remove local admin on Windows Server?:

                      @Pete-S said in Is it possibe to remove local admin on Windows Server?:

                      ve the local admin account on Windows Server that belongs to a domain? Or prevent logins.
                      Or is always possible to login as local admin (if you know the name/passwd)?

                      I wouldn't disable the local admin of a server, it would come handy if you need to restore stuff or remove and add from the domain. LAPS works but beware 🙂

                      I agree with @dbeato. When sh$% hits the fan with the server, no networking or no cached credentials, you will long for a local admin account.

                      I do disable the Administrator account after creating my own local admin with 20+ char strong password. Less worries on both the security and DR front.

                      Yes, but if you have physical or kvm access, even virtual, you can use linux ntpass to turn on the admin account and reset the password. This would be the last resort if you really lost the admin access, which is rare.

                      Not since UEFI... At least it doesn't work with Windows 10 and subsequent kernels.

                      I can imagine you had problems because of bitlocker or something similar, but not UEFI, unless the system was locked out to only boot a certain way through config. Maybe you could test a UEFI boot with a Hiren's USB boot just for fun?

                      dbeatoD 1 Reply Last reply Reply Quote 1
                      • dbeatoD
                        dbeato @Grey
                        last edited by

                        @Grey said in Is it possibe to remove local admin on Windows Server?:

                        @dbeato said in Is it possibe to remove local admin on Windows Server?:

                        @Grey said in Is it possibe to remove local admin on Windows Server?:

                        @pmoncho said in Is it possibe to remove local admin on Windows Server?:

                        @dbeato said in Is it possibe to remove local admin on Windows Server?:

                        @Pete-S said in Is it possibe to remove local admin on Windows Server?:

                        ve the local admin account on Windows Server that belongs to a domain? Or prevent logins.
                        Or is always possible to login as local admin (if you know the name/passwd)?

                        I wouldn't disable the local admin of a server, it would come handy if you need to restore stuff or remove and add from the domain. LAPS works but beware 🙂

                        I agree with @dbeato. When sh$% hits the fan with the server, no networking or no cached credentials, you will long for a local admin account.

                        I do disable the Administrator account after creating my own local admin with 20+ char strong password. Less worries on both the security and DR front.

                        Yes, but if you have physical or kvm access, even virtual, you can use linux ntpass to turn on the admin account and reset the password. This would be the last resort if you really lost the admin access, which is rare.

                        Not since UEFI... At least it doesn't work with Windows 10 and subsequent kernels.

                        I can imagine you had problems because of bitlocker or something similar, but not UEFI, unless the system was locked out to only boot a certain way through config. Maybe you could test a UEFI boot with a Hiren's USB boot just for fun?

                        I have tried with the latest Hiren's Boot drive and still doesn't work for Windows 10 for some reason in UEFI... Even if it was bitlocker I could always decrypt and then use it if worked properly. At least the old ntpasswd didn't work (this one https://pogostick.net/~pnh/ntpasswd/) With WIndows 10. Just for giggles I will try it on a VM today with this https://www.hirensbootcd.org/howtos/

                        black3dynamiteB 1 Reply Last reply Reply Quote 0
                        • black3dynamiteB
                          black3dynamite @dbeato
                          last edited by

                          @dbeato said in Is it possibe to remove local admin on Windows Server?:

                          @Grey said in Is it possibe to remove local admin on Windows Server?:

                          @dbeato said in Is it possibe to remove local admin on Windows Server?:

                          @Grey said in Is it possibe to remove local admin on Windows Server?:

                          @pmoncho said in Is it possibe to remove local admin on Windows Server?:

                          @dbeato said in Is it possibe to remove local admin on Windows Server?:

                          @Pete-S said in Is it possibe to remove local admin on Windows Server?:

                          ve the local admin account on Windows Server that belongs to a domain? Or prevent logins.
                          Or is always possible to login as local admin (if you know the name/passwd)?

                          I wouldn't disable the local admin of a server, it would come handy if you need to restore stuff or remove and add from the domain. LAPS works but beware 🙂

                          I agree with @dbeato. When sh$% hits the fan with the server, no networking or no cached credentials, you will long for a local admin account.

                          I do disable the Administrator account after creating my own local admin with 20+ char strong password. Less worries on both the security and DR front.

                          Yes, but if you have physical or kvm access, even virtual, you can use linux ntpass to turn on the admin account and reset the password. This would be the last resort if you really lost the admin access, which is rare.

                          Not since UEFI... At least it doesn't work with Windows 10 and subsequent kernels.

                          I can imagine you had problems because of bitlocker or something similar, but not UEFI, unless the system was locked out to only boot a certain way through config. Maybe you could test a UEFI boot with a Hiren's USB boot just for fun?

                          I have tried with the latest Hiren's Boot drive and still doesn't work for Windows 10 for some reason in UEFI... Even if it was bitlocker I could always decrypt and then use it if worked properly. At least the old ntpasswd didn't work (this one https://pogostick.net/~pnh/ntpasswd/) With WIndows 10. Just for giggles I will try it on a VM today with this https://www.hirensbootcd.org/howtos/

                          You just use Ubuntu, enable the repo that provides chntpw package to make changes to Windows accounts?

                          dbeatoD 1 Reply Last reply Reply Quote 0
                          • dbeatoD
                            dbeato @black3dynamite
                            last edited by

                            @black3dynamite said in Is it possibe to remove local admin on Windows Server?:

                            @dbeato said in Is it possibe to remove local admin on Windows Server?:

                            @Grey said in Is it possibe to remove local admin on Windows Server?:

                            @dbeato said in Is it possibe to remove local admin on Windows Server?:

                            @Grey said in Is it possibe to remove local admin on Windows Server?:

                            @pmoncho said in Is it possibe to remove local admin on Windows Server?:

                            @dbeato said in Is it possibe to remove local admin on Windows Server?:

                            @Pete-S said in Is it possibe to remove local admin on Windows Server?:

                            ve the local admin account on Windows Server that belongs to a domain? Or prevent logins.
                            Or is always possible to login as local admin (if you know the name/passwd)?

                            I wouldn't disable the local admin of a server, it would come handy if you need to restore stuff or remove and add from the domain. LAPS works but beware 🙂

                            I agree with @dbeato. When sh$% hits the fan with the server, no networking or no cached credentials, you will long for a local admin account.

                            I do disable the Administrator account after creating my own local admin with 20+ char strong password. Less worries on both the security and DR front.

                            Yes, but if you have physical or kvm access, even virtual, you can use linux ntpass to turn on the admin account and reset the password. This would be the last resort if you really lost the admin access, which is rare.

                            Not since UEFI... At least it doesn't work with Windows 10 and subsequent kernels.

                            I can imagine you had problems because of bitlocker or something similar, but not UEFI, unless the system was locked out to only boot a certain way through config. Maybe you could test a UEFI boot with a Hiren's USB boot just for fun?

                            I have tried with the latest Hiren's Boot drive and still doesn't work for Windows 10 for some reason in UEFI... Even if it was bitlocker I could always decrypt and then use it if worked properly. At least the old ntpasswd didn't work (this one https://pogostick.net/~pnh/ntpasswd/) With WIndows 10. Just for giggles I will try it on a VM today with this https://www.hirensbootcd.org/howtos/

                            You just use Ubuntu, enable the repo that provides chntpw package to make changes to Windows accounts?

                            Yeah, I have used that.

                            1 Reply Last reply Reply Quote 0
                            • 1 / 1
                            • First post
                              Last post