ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    Is it possibe to remove local admin on Windows Server?

    IT Discussion
    6
    15
    354
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • WLS-ITGuyW
      WLS-ITGuy @Grey
      last edited by

      @Grey said in Is it possibe to remove local admin on Windows Server?:

      A better solution: https://www.microsoft.com/en-us/download/details.aspx?id=46899

      Definitely a better option.

      1 1 Reply Last reply Reply Quote 0
      • 1
        1337 @WLS-ITGuy
        last edited by

        @WLS-ITGuy said in Is it possibe to remove local admin on Windows Server?:

        @Grey said in Is it possibe to remove local admin on Windows Server?:

        A better solution: https://www.microsoft.com/en-us/download/details.aspx?id=46899

        Definitely a better option.

        Ah, so it sets a unique password for local admin on every server and saves those password in the AD so people can find out what the password is?

        GreyG 1 Reply Last reply Reply Quote 0
        • dbeatoD
          dbeato
          last edited by

          @Pete-S said in Is it possibe to remove local admin on Windows Server?:

          ve the local admin account on Windows Server that belongs to a domain? Or prevent logins.
          Or is always possible to login as local admin (if you know the name/passwd)?

          I wouldn't disable the local admin of a server, it would come handy if you need to restore stuff or remove and add from the domain. LAPS works but beware 🙂

          pmonchoP 1 Reply Last reply Reply Quote 1
          • pmonchoP
            pmoncho @dbeato
            last edited by

            @dbeato said in Is it possibe to remove local admin on Windows Server?:

            @Pete-S said in Is it possibe to remove local admin on Windows Server?:

            ve the local admin account on Windows Server that belongs to a domain? Or prevent logins.
            Or is always possible to login as local admin (if you know the name/passwd)?

            I wouldn't disable the local admin of a server, it would come handy if you need to restore stuff or remove and add from the domain. LAPS works but beware 🙂

            I agree with @dbeato. When sh$% hits the fan with the server, no networking or no cached credentials, you will long for a local admin account.

            I do disable the Administrator account after creating my own local admin with 20+ char strong password. Less worries on both the security and DR front.

            GreyG 1 Reply Last reply Reply Quote 1
            • GreyG
              Grey @1337
              last edited by

              @Pete-S said in Is it possibe to remove local admin on Windows Server?:

              @WLS-ITGuy said in Is it possibe to remove local admin on Windows Server?:

              @Grey said in Is it possibe to remove local admin on Windows Server?:

              A better solution: https://www.microsoft.com/en-us/download/details.aspx?id=46899

              Definitely a better option.

              Ah, so it sets a unique password for local admin on every server and saves those password in the AD so people can find out what the password is?

              Correct.

              1 Reply Last reply Reply Quote 0
              • GreyG
                Grey @pmoncho
                last edited by

                @pmoncho said in Is it possibe to remove local admin on Windows Server?:

                @dbeato said in Is it possibe to remove local admin on Windows Server?:

                @Pete-S said in Is it possibe to remove local admin on Windows Server?:

                ve the local admin account on Windows Server that belongs to a domain? Or prevent logins.
                Or is always possible to login as local admin (if you know the name/passwd)?

                I wouldn't disable the local admin of a server, it would come handy if you need to restore stuff or remove and add from the domain. LAPS works but beware 🙂

                I agree with @dbeato. When sh$% hits the fan with the server, no networking or no cached credentials, you will long for a local admin account.

                I do disable the Administrator account after creating my own local admin with 20+ char strong password. Less worries on both the security and DR front.

                Yes, but if you have physical or kvm access, even virtual, you can use linux ntpass to turn on the admin account and reset the password. This would be the last resort if you really lost the admin access, which is rare.

                dbeatoD 1 Reply Last reply Reply Quote 0
                • dbeatoD
                  dbeato @Grey
                  last edited by

                  @Grey said in Is it possibe to remove local admin on Windows Server?:

                  @pmoncho said in Is it possibe to remove local admin on Windows Server?:

                  @dbeato said in Is it possibe to remove local admin on Windows Server?:

                  @Pete-S said in Is it possibe to remove local admin on Windows Server?:

                  ve the local admin account on Windows Server that belongs to a domain? Or prevent logins.
                  Or is always possible to login as local admin (if you know the name/passwd)?

                  I wouldn't disable the local admin of a server, it would come handy if you need to restore stuff or remove and add from the domain. LAPS works but beware 🙂

                  I agree with @dbeato. When sh$% hits the fan with the server, no networking or no cached credentials, you will long for a local admin account.

                  I do disable the Administrator account after creating my own local admin with 20+ char strong password. Less worries on both the security and DR front.

                  Yes, but if you have physical or kvm access, even virtual, you can use linux ntpass to turn on the admin account and reset the password. This would be the last resort if you really lost the admin access, which is rare.

                  Not since UEFI... At least it doesn't work with Windows 10 and subsequent kernels.

                  GreyG 1 Reply Last reply Reply Quote 1
                  • GreyG
                    Grey @dbeato
                    last edited by

                    @dbeato said in Is it possibe to remove local admin on Windows Server?:

                    @Grey said in Is it possibe to remove local admin on Windows Server?:

                    @pmoncho said in Is it possibe to remove local admin on Windows Server?:

                    @dbeato said in Is it possibe to remove local admin on Windows Server?:

                    @Pete-S said in Is it possibe to remove local admin on Windows Server?:

                    ve the local admin account on Windows Server that belongs to a domain? Or prevent logins.
                    Or is always possible to login as local admin (if you know the name/passwd)?

                    I wouldn't disable the local admin of a server, it would come handy if you need to restore stuff or remove and add from the domain. LAPS works but beware 🙂

                    I agree with @dbeato. When sh$% hits the fan with the server, no networking or no cached credentials, you will long for a local admin account.

                    I do disable the Administrator account after creating my own local admin with 20+ char strong password. Less worries on both the security and DR front.

                    Yes, but if you have physical or kvm access, even virtual, you can use linux ntpass to turn on the admin account and reset the password. This would be the last resort if you really lost the admin access, which is rare.

                    Not since UEFI... At least it doesn't work with Windows 10 and subsequent kernels.

                    I can imagine you had problems because of bitlocker or something similar, but not UEFI, unless the system was locked out to only boot a certain way through config. Maybe you could test a UEFI boot with a Hiren's USB boot just for fun?

                    dbeatoD 1 Reply Last reply Reply Quote 1
                    • dbeatoD
                      dbeato @Grey
                      last edited by

                      @Grey said in Is it possibe to remove local admin on Windows Server?:

                      @dbeato said in Is it possibe to remove local admin on Windows Server?:

                      @Grey said in Is it possibe to remove local admin on Windows Server?:

                      @pmoncho said in Is it possibe to remove local admin on Windows Server?:

                      @dbeato said in Is it possibe to remove local admin on Windows Server?:

                      @Pete-S said in Is it possibe to remove local admin on Windows Server?:

                      ve the local admin account on Windows Server that belongs to a domain? Or prevent logins.
                      Or is always possible to login as local admin (if you know the name/passwd)?

                      I wouldn't disable the local admin of a server, it would come handy if you need to restore stuff or remove and add from the domain. LAPS works but beware 🙂

                      I agree with @dbeato. When sh$% hits the fan with the server, no networking or no cached credentials, you will long for a local admin account.

                      I do disable the Administrator account after creating my own local admin with 20+ char strong password. Less worries on both the security and DR front.

                      Yes, but if you have physical or kvm access, even virtual, you can use linux ntpass to turn on the admin account and reset the password. This would be the last resort if you really lost the admin access, which is rare.

                      Not since UEFI... At least it doesn't work with Windows 10 and subsequent kernels.

                      I can imagine you had problems because of bitlocker or something similar, but not UEFI, unless the system was locked out to only boot a certain way through config. Maybe you could test a UEFI boot with a Hiren's USB boot just for fun?

                      I have tried with the latest Hiren's Boot drive and still doesn't work for Windows 10 for some reason in UEFI... Even if it was bitlocker I could always decrypt and then use it if worked properly. At least the old ntpasswd didn't work (this one https://pogostick.net/~pnh/ntpasswd/) With WIndows 10. Just for giggles I will try it on a VM today with this https://www.hirensbootcd.org/howtos/

                      black3dynamiteB 1 Reply Last reply Reply Quote 0
                      • black3dynamiteB
                        black3dynamite @dbeato
                        last edited by

                        @dbeato said in Is it possibe to remove local admin on Windows Server?:

                        @Grey said in Is it possibe to remove local admin on Windows Server?:

                        @dbeato said in Is it possibe to remove local admin on Windows Server?:

                        @Grey said in Is it possibe to remove local admin on Windows Server?:

                        @pmoncho said in Is it possibe to remove local admin on Windows Server?:

                        @dbeato said in Is it possibe to remove local admin on Windows Server?:

                        @Pete-S said in Is it possibe to remove local admin on Windows Server?:

                        ve the local admin account on Windows Server that belongs to a domain? Or prevent logins.
                        Or is always possible to login as local admin (if you know the name/passwd)?

                        I wouldn't disable the local admin of a server, it would come handy if you need to restore stuff or remove and add from the domain. LAPS works but beware 🙂

                        I agree with @dbeato. When sh$% hits the fan with the server, no networking or no cached credentials, you will long for a local admin account.

                        I do disable the Administrator account after creating my own local admin with 20+ char strong password. Less worries on both the security and DR front.

                        Yes, but if you have physical or kvm access, even virtual, you can use linux ntpass to turn on the admin account and reset the password. This would be the last resort if you really lost the admin access, which is rare.

                        Not since UEFI... At least it doesn't work with Windows 10 and subsequent kernels.

                        I can imagine you had problems because of bitlocker or something similar, but not UEFI, unless the system was locked out to only boot a certain way through config. Maybe you could test a UEFI boot with a Hiren's USB boot just for fun?

                        I have tried with the latest Hiren's Boot drive and still doesn't work for Windows 10 for some reason in UEFI... Even if it was bitlocker I could always decrypt and then use it if worked properly. At least the old ntpasswd didn't work (this one https://pogostick.net/~pnh/ntpasswd/) With WIndows 10. Just for giggles I will try it on a VM today with this https://www.hirensbootcd.org/howtos/

                        You just use Ubuntu, enable the repo that provides chntpw package to make changes to Windows accounts?

                        dbeatoD 1 Reply Last reply Reply Quote 0
                        • dbeatoD
                          dbeato @black3dynamite
                          last edited by

                          @black3dynamite said in Is it possibe to remove local admin on Windows Server?:

                          @dbeato said in Is it possibe to remove local admin on Windows Server?:

                          @Grey said in Is it possibe to remove local admin on Windows Server?:

                          @dbeato said in Is it possibe to remove local admin on Windows Server?:

                          @Grey said in Is it possibe to remove local admin on Windows Server?:

                          @pmoncho said in Is it possibe to remove local admin on Windows Server?:

                          @dbeato said in Is it possibe to remove local admin on Windows Server?:

                          @Pete-S said in Is it possibe to remove local admin on Windows Server?:

                          ve the local admin account on Windows Server that belongs to a domain? Or prevent logins.
                          Or is always possible to login as local admin (if you know the name/passwd)?

                          I wouldn't disable the local admin of a server, it would come handy if you need to restore stuff or remove and add from the domain. LAPS works but beware 🙂

                          I agree with @dbeato. When sh$% hits the fan with the server, no networking or no cached credentials, you will long for a local admin account.

                          I do disable the Administrator account after creating my own local admin with 20+ char strong password. Less worries on both the security and DR front.

                          Yes, but if you have physical or kvm access, even virtual, you can use linux ntpass to turn on the admin account and reset the password. This would be the last resort if you really lost the admin access, which is rare.

                          Not since UEFI... At least it doesn't work with Windows 10 and subsequent kernels.

                          I can imagine you had problems because of bitlocker or something similar, but not UEFI, unless the system was locked out to only boot a certain way through config. Maybe you could test a UEFI boot with a Hiren's USB boot just for fun?

                          I have tried with the latest Hiren's Boot drive and still doesn't work for Windows 10 for some reason in UEFI... Even if it was bitlocker I could always decrypt and then use it if worked properly. At least the old ntpasswd didn't work (this one https://pogostick.net/~pnh/ntpasswd/) With WIndows 10. Just for giggles I will try it on a VM today with this https://www.hirensbootcd.org/howtos/

                          You just use Ubuntu, enable the repo that provides chntpw package to make changes to Windows accounts?

                          Yeah, I have used that.

                          1 Reply Last reply Reply Quote 0
                          • 1 / 1
                          • First post
                            Last post