Solved

Audit Administrator Account

Posted on 2011-03-09
3
664 Views
Last Modified: 2012-06-27
Having reviewed this answer, I'm still left with quesstions..Securing the Domain Administrator account, (Q_22094429)

Do processes that have been set up previously under the Domain Admin account "break" if you change the password? (I'm guessing yes!)
If so, surely it's impossible to "Audit" all instances of the Administrators account being used, should one need to secure the account at short notice.
I need to change the password for the Domain Administrator and create a new "Support" password. (i.e It's not possible for me to have my users "forget" the existing password.)
If it was possible to change the password, without effecting any of the day to day processes, then that would be perfect. I would also need to "lock" the Domain Admin password to ensure my Support users couldn't reset it.
0
Comment
Question by:BlueprintConsultant
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
3 Comments
 
LVL 57

Accepted Solution

by:
Mike Kline earned 250 total points
ID: 35084234
Yes if services are using that account and you don't update the PW that will break

You could try out a script to ID what accounts are being used

http://theessentialexchange.com/blogs/michael/archive/2007/11/13/finding-services-using-non-system-accounts.aspx

I haven't tested that script myself but Michael Smith is good.

By the way Microsoft knows this is an issue and introduced Managed Service Accounts in 2008 R2  http://technet.microsoft.com/en-us/library/dd560633(WS.10).aspx

MSA's are not perfect but a good start.

Thanks

Mike
0
 

Author Comment

by:BlueprintConsultant
ID: 35110907
"Yes if services are using that account and you don't update the PW that will break"

Can I just check that you mean , It WILL break the service if I change the password? - that little bit of your reply wasn't 100% clear!

The rest was excellent, I'm giving it a quick look, and will be back in a day or two..
0
 

Author Comment

by:BlueprintConsultant
ID: 35254963
That was a good tip to try the Code BY Michael Smith. (The code for a non-VB expert was slightly tricky to get round - the missing tip from his tutorial was, after saving the code as a .vbs file then you had to drag and drop the "list of computers" file you created, onto the actual vbs program for it to execute...once I'd figured that out, it went very well.)
Thanks MKline71!
0

Featured Post

Are your AD admin tools letting you down?

Managing Active Directory can get complicated.  Often, the native tools for managing AD are just not up to the task.  The largest Active Directory installations in the world have relied on one tool to manage their day-to-day administration tasks: Hyena. Start your trial today.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Uncontrolled local administrators groups within any organization pose a huge security risk. Because these groups are locally managed it becomes difficult to audit and maintain them.
How many times a day do you open, acknowledge, or close an IT incident? What’s your process? Do you have a process depending on the incident, systems involved, and other factors? New Relic Alerts gives you options for how you interact with notifica…
This video shows how to use Hyena, from SystemTools Software, to bulk import 100 user accounts from an external text file. View in 1080p for best video quality.
This video shows how to use Hyena, from SystemTools Software, to update 100 user accounts from an external text file. View in 1080p for best video quality.

687 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question