ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    Local Admin PW

    Scheduled Pinned Locked Moved IT Discussion
    35 Posts 10 Posters 2.9k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • jmooreJ
      jmoore @dafyre
      last edited by

      @dafyre My boss told me that microsoft took away the ability to change the passwords via gpo because of some issue where they were being sent in plain text. I have no way to verify but thats what he told me

      scottalanmillerS dafyreD coliverC Mike DavisM 4 Replies Last reply Reply Quote 1
      • scottalanmillerS
        scottalanmiller @jmoore
        last edited by

        @jmoore said in Local Admin PW:

        @dafyre My boss told me that microsoft took away the ability to change the passwords via gpo because of some issue where they were being sent in plain text. I have no way to verify but thats what he told me

        But he also told you that it was still happening. Can't be both.

        jmooreJ F 2 Replies Last reply Reply Quote 1
        • dafyreD
          dafyre @jmoore
          last edited by

          @jmoore said in Local Admin PW:

          @dafyre My boss told me that microsoft took away the ability to change the passwords via gpo because of some issue where they were being sent in plain text. I have no way to verify but thats what he told me

          Seems like I remember hearing about that somewhere. Salt can do this, but I've not tested it on Windows yet.

          scottalanmillerS 1 Reply Last reply Reply Quote 0
          • scottalanmillerS
            scottalanmiller @dafyre
            last edited by

            @dafyre said in Local Admin PW:

            @jmoore said in Local Admin PW:

            @dafyre My boss told me that microsoft took away the ability to change the passwords via gpo because of some issue where they were being sent in plain text. I have no way to verify but thats what he told me

            Seems like I remember hearing about that somewhere. Salt can do this, but I've not tested it on Windows yet.

            Yes, Salt definitely can.

            1 Reply Last reply Reply Quote 0
            • jmooreJ
              jmoore @scottalanmiller
              last edited by

              @scottalanmiller said in Local Admin PW:

              @jmoore said in Local Admin PW:

              @dafyre My boss told me that microsoft took away the ability to change the passwords via gpo because of some issue where they were being sent in plain text. I have no way to verify but thats what he told me

              But he also told you that it was still happening. Can't be both.

              your exactly right. I see the dichotomy there. I guess i don't understand what he meant.

              1 Reply Last reply Reply Quote 0
              • dbeatoD
                dbeato
                last edited by

                If you are in a Windows Environment take a look at LAPS
                https://technet.microsoft.com/en-us/mt227395.aspx

                jmooreJ 1 Reply Last reply Reply Quote 0
                • ObsolesceO
                  Obsolesce
                  last edited by Obsolesce

                  I was thinking some kind of PS script would work... first result of a search lead to this, which looks promising:

                  http://beta.itprotoday.com/management-mobility/resetting-local-administrator-password-computers

                  scottalanmillerS jmooreJ 2 Replies Last reply Reply Quote 0
                  • scottalanmillerS
                    scottalanmiller @Obsolesce
                    last edited by

                    @tim_g said in Local Admin PW:

                    I was thinking some kind of PS script would work... first result of a search lead to this, which looks promising:

                    PS could definitely do it.

                    1 Reply Last reply Reply Quote 0
                    • jmooreJ
                      jmoore @Obsolesce
                      last edited by

                      @tim_g said in Local Admin PW:

                      I was thinking some kind of PS script would work... first result of a search lead to this, which looks promising:

                      http://beta.itprotoday.com/management-mobility/resetting-local-administrator-password-computers

                      thanks tim, checking that out too

                      1 Reply Last reply Reply Quote 0
                      • jmooreJ
                        jmoore @dbeato
                        last edited by

                        @dbeato said in Local Admin PW:

                        If you are in a Windows Environment take a look at LAPS
                        https://technet.microsoft.com/en-us/mt227395.aspx

                        thanks dbeato, i will look at that

                        1 Reply Last reply Reply Quote 1
                        • F
                          flaxking @scottalanmiller
                          last edited by flaxking

                          @scottalanmiller said in Local Admin PW:

                          @jmoore said in Local Admin PW:

                          @dafyre My boss told me that microsoft took away the ability to change the passwords via gpo because of some issue where they were being sent in plain text. I have no way to verify but thats what he told me

                          But he also told you that it was still happening. Can't be both.

                          Are you sure it can't be? My guess is that whatever update removes this ability might not remove an existing GPO with it already setup (in which case there probably is a hacky way to change the password). Or maybe his boss just thinks it is still happening, I couldn't really tell you.

                          DustinB3403D scottalanmillerS jmooreJ 3 Replies Last reply Reply Quote 0
                          • DustinB3403D
                            DustinB3403 @flaxking
                            last edited by

                            @flaxking said in Local Admin PW:

                            @scottalanmiller said in Local Admin PW:

                            @jmoore said in Local Admin PW:

                            @dafyre My boss told me that microsoft took away the ability to change the passwords via gpo because of some issue where they were being sent in plain text. I have no way to verify but thats what he told me

                            But he also told you that it was still happening. Can't be both.

                            Are you sure it can't be? My guess is that whatever update removes this ability might not remove an existing GPO with it already setup. Or maybe his boss just thinks it is still happening, I couldn't really tell you.

                            There would be an easy way to test.

                            Change the password locally, reboot, perform a gpupdate and see if the old password works again.

                            jmooreJ 1 Reply Last reply Reply Quote 1
                            • scottalanmillerS
                              scottalanmiller @flaxking
                              last edited by

                              @flaxking said in Local Admin PW:

                              @scottalanmiller said in Local Admin PW:

                              @jmoore said in Local Admin PW:

                              @dafyre My boss told me that microsoft took away the ability to change the passwords via gpo because of some issue where they were being sent in plain text. I have no way to verify but thats what he told me

                              But he also told you that it was still happening. Can't be both.

                              Are you sure it can't be? My guess is that whatever update removes this ability might not remove an existing GPO with it already setup (in which case there probably is a hacky way to change the password). Or maybe his boss just thinks it is still happening, I couldn't really tell you.

                              There is no reason to think that. Implementing one system would not imply any removal of another. Just as how GPO doesn't remove any other system.

                              1 Reply Last reply Reply Quote 0
                              • coliverC
                                coliver @jmoore
                                last edited by

                                @jmoore said in Local Admin PW:

                                @dafyre My boss told me that microsoft took away the ability to change the passwords via gpo because of some issue where they were being sent in plain text. I have no way to verify but thats what he told me

                                I don't think it was plain text but it was such a weak cipher it might as well have been.

                                jmooreJ 1 Reply Last reply Reply Quote 0
                                • jmooreJ
                                  jmoore @coliver
                                  last edited by

                                  @coliver said in Local Admin PW:

                                  @jmoore said in Local Admin PW:

                                  @dafyre My boss told me that microsoft took away the ability to change the passwords via gpo because of some issue where they were being sent in plain text. I have no way to verify but thats what he told me

                                  I don't think it was plain text but it was such a weak cipher it might as well have been.

                                  got it. one and the same to him I am guessing

                                  1 Reply Last reply Reply Quote 0
                                  • jmooreJ
                                    jmoore @flaxking
                                    last edited by

                                    @flaxking said in Local Admin PW:

                                    @scottalanmiller said in Local Admin PW:

                                    @jmoore said in Local Admin PW:

                                    @dafyre My boss told me that microsoft took away the ability to change the passwords via gpo because of some issue where they were being sent in plain text. I have no way to verify but thats what he told me

                                    But he also told you that it was still happening. Can't be both.

                                    Are you sure it can't be? My guess is that whatever update removes this ability might not remove an existing GPO with it already setup (in which case there probably is a hacky way to change the password). Or maybe his boss just thinks it is still happening, I couldn't really tell you.

                                    Well he definitely said both. So maybe Microsoft took away his ability to change passwords but the gpo itself still remembers the last one and so will change it back if I go and change it ?

                                    coliverC 1 Reply Last reply Reply Quote 0
                                    • jmooreJ
                                      jmoore @DustinB3403
                                      last edited by

                                      @dustinb3403 said in Local Admin PW:

                                      @flaxking said in Local Admin PW:

                                      @scottalanmiller said in Local Admin PW:

                                      @jmoore said in Local Admin PW:

                                      @dafyre My boss told me that microsoft took away the ability to change the passwords via gpo because of some issue where they were being sent in plain text. I have no way to verify but thats what he told me

                                      But he also told you that it was still happening. Can't be both.

                                      Are you sure it can't be? My guess is that whatever update removes this ability might not remove an existing GPO with it already setup. Or maybe his boss just thinks it is still happening, I couldn't really tell you.

                                      There would be an easy way to test.

                                      Change the password locally, reboot, perform a gpupdate and see if the old password works again.

                                      testing that now that i have a few min free time

                                      1 Reply Last reply Reply Quote 0
                                      • gjacobseG
                                        gjacobse
                                        last edited by gjacobse

                                        This is the simple Net Use I came up with. Granted I was running it through the ScreenConnect COMMAND line tool,.. but it worked every time.

                                        net user USERNAME "Pa$$w0rd149" /add /passwordreq:yes /fullname:"User Name" && net localgroup administrators USERNAME /add
                                        

                                        You can do this via Powershell - but I don't have that yet.

                                        1 Reply Last reply Reply Quote 0
                                        • Mike DavisM
                                          Mike Davis @jmoore
                                          last edited by

                                          @jmoore said in Local Admin PW:

                                          @dafyre My boss told me that microsoft took away the ability to change the passwords via gpo because of some issue where they were being sent in plain text. I have no way to verify but thats what he told me

                                          This is true. An automatic update now disables the ability to change the password if you were setting it that way. If you try to edit an existing policy, you get this warning:
                                          0_1508893436447_AD-localuser1.png

                                          And if you click OK, you get this where the password field is disabled:
                                          0_1508893468138_AD-localuser2.png

                                          1 Reply Last reply Reply Quote 0
                                          • Mike DavisM
                                            Mike Davis
                                            last edited by

                                            Oddly enough, the password seems to be encrypted when you view the Groups.xml file that creates that policy, but maybe it doesn't take much to reverse it. The code looks like this:

                                            <?xml version="1.0" encoding="UTF-8"?>
                                            
                                            -<Groups clsid="{3125E937-EB16-4b4c-9934-54123DEA4D26}">
                                            
                                            
                                            -<User clsid="{DF5F1855-51E5-4d24-8B1A-D9AD348BA1D1}" removePolicy="0" userContext="0" uid="{E2123A2D-7D20-4C9A-A2C9-474CFAF1E5FE}" changed="2017-01-25 14:28:38" image="2" name="user">
                                            
                                            <Properties userName="user" subAuthority="" acctDisabled="0" neverExpires="1" noChange="1" changeLogon="0" cpassword="TAF+vMr9+ieePdksvnsN/2i0T+u3P5E+PQ08jnVEgHs" description="" fullName="" newName="" action="U"/>
                                            
                                            </User>
                                            
                                            
                                            -<Group clsid="{6D4A79E4-529C-4481-ABD0-F5BD7EA93BA7}" uid="{617359A3-9040-4F00-BFED-0FE86588FAF1}" changed="2017-01-25 14:31:18" image="2" name="Administrators (built-in)">
                                            
                                            
                                            -<Properties description="" newName="" action="U" groupName="Administrators (built-in)" groupSid="S-1-5-32-544" removeAccounts="0" deleteAllGroups="0" deleteAllUsers="0">
                                            
                                            
                                            -<Members>
                                            
                                            <Member name=".\user" action="ADD" sid=""/>
                                            
                                            </Members>
                                            
                                            </Properties>
                                            
                                            </Group>
                                            
                                            </Groups>
                                            
                                            1 Reply Last reply Reply Quote 0
                                            • 1
                                            • 2
                                            • 2 / 2
                                            • First post
                                              Last post