rename Administrator account well after initial set-up

rename Administrator account well after initial set-up

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
rename Administrator account well after initial set-up Patrick Lublin 01-04-2006
Posted by =?Utf-8?B?UGF0cmljayBMdWJsaW4= on January 4, 2006, 4:28 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
I would like to rename the Administrator account in our Server 2003 AD
domain. However, all of the servers have been deployed and used for some time
without renaming the account. How do I accomplish this safely? What are the
risks?

Thanks!

Posted by Lanwench [MVP - Exchange] on January 4, 2006, 4:31 pm
If you were  Registered and logged in, you could reply and use other advanced thread options


> I would like to rename the Administrator account in our Server 2003 AD
> domain. However, all of the servers have been deployed and used for
> some time without renaming the account. How do I accomplish this
> safely? What are the risks?
>
> Thanks!

Make sure you aren't using the built-in admin credentials to run any
scheduled tasks, or services - it's bad practice anyway. If you are, I
suggest you change it - or remember where to change the credentials wherever
you've set them.

Outside of this, there isn't really much risk, as long as all the servers
are up & running and can see each other.

I usually like to copy the admin account as a backup, so I don't have only
one, before doing something like this - just in case - but it's not a big
deal to do, overall.



Posted by . on January 4, 2006, 5:02 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
If you're referring to the local admin account, don't bother. It's a useless
endeavor. No matter what the account is named, it's RID is always 500.

Ray

>I would like to rename the Administrator account in our Server 2003 AD
> domain. However, all of the servers have been deployed and used for some
> time
> without renaming the account. How do I accomplish this safely? What are
> the
> risks?
>
> Thanks!



Posted by =?Utf-8?B?RGF2aWQgRGF2aXM=?= on January 4, 2006, 5:51 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
If you are referring to the Domain admin account, then you can simply us AD
users and computers to rename the account. Be sure to either be logged on as
another administrator or immediately log off as soon as you rename the
account. Also, ensure that you are not logged on to other machines with the
account that you are renaming.

If you are referring to the local admin account, there is no such thing on a
domain controller. However on a member server you can use computer management
and local user and computers MMC to change the account. There should not be
any adverse problems changing domain or local account name, unless you have
services or scripts that use them. If so you will need to make the necessarry
changes.
--
David Davis [MCSE, CCNA, Security +]



"Patrick Lublin" wrote:

> I would like to rename the Administrator account in our Server 2003 AD
> domain. However, all of the servers have been deployed and used for some time
> without renaming the account. How do I accomplish this safely? What are the
> risks?
>
> Thanks!

Posted by Roger Abell [MVP] on January 5, 2006, 8:16 am
If you were  Registered and logged in, you could reply and use other advanced thread options
There is a setting in the security options section of group policy
to rename the built-in administrator account
If this is used in a gpo that has the DCs within its scope then
this changes the name of that account in the domain.
If this is used in a gpo that has other (non dc) machines within
its scope it gets renamed on those machines
If use with both then on both, etc. so that if linked to the domain
the gpo changes the name everywhere.

Lanwench rightly has named the main pitfalls relative to where
the account may commonly be found in use.



>I would like to rename the Administrator account in our Server 2003 AD
> domain. However, all of the servers have been deployed and used for some
> time
> without renaming the account. How do I accomplish this safely? What are
> the
> risks?
>
> Thanks!



Similar ThreadsPosted
should i have to rename administrator on domain server. April 24, 2006, 2:46 pm
Renamed Local Administrator Account Name Reverts to Old Account Name November 30, 2005, 4:39 am
Renaming "Administrator" account October 20, 2005, 12:18 pm
Administrator account and lockout policy July 15, 2008, 12:35 pm
How does your organizations manage the local administrator account on workstations? August 29, 2008, 11:32 pm
Initial post on windowsxp.help_and_support September 16, 2005, 3:38 am
Slow FTP initial connection through XP firewall August 23, 2006, 12:15 pm
Rename running process (can't) March 15, 2006, 4:39 pm
Permissions to Rename a Computer within an AD domain February 16, 2006, 10:10 am
NTFS Rename vs Delete permissions February 28, 2006, 2:07 pm

The site map in XML format XML site map

Contact Us | Privacy Policy