Solved

prevent reset password on windows server 2008 r2

Posted on 2013-01-20
7
460 Views
Last Modified: 2013-05-12
how am i prevent anyone to reset windows server 2008/12 administrator password, he can reboot my server and can direct touch my server
0
Comment
Question by:john80988
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2
  • 2
7 Comments
 
LVL 96

Expert Comment

by:Experienced Member
ID: 38798290
An administrator can change the administrator's password. I don't think there is any way around that.

You can make the user in question a non-administrator and give them roles that they can do. There are a numberof different groups in Active Director, Users and Groups.

... Thinkpads_User
0
 

Author Comment

by:john80988
ID: 38798390
i mean if he is not administrator, but he was using some trick that can access, back hack the password
0
 
LVL 96

Accepted Solution

by:
Experienced Member earned 500 total points
ID: 38798396
If the user is not the adminstrator and does not know the administrator password, then they cannot change the administrator password. There is no Windows back door into this.

There may be hacking tools that a person could try, but presumably you have more faith in your user than this. You would also find your server being restarted unnecessarily.

... Thinkpads_User
0
VIDEO: THE CONCERTO CLOUD FOR HEALTHCARE

Modern healthcare requires a modern cloud. View this brief video to understand how the Concerto Cloud for Healthcare can help your organization.

 
LVL 55

Expert Comment

by:McKnife
ID: 38799287
I am sure you are talking about the various offline attacks that you can achieve with boot CDs.
All these attacks fail if you encrypt the servers. Use Bitlocker to encrypt the server.

...however this produces another problem: how to provide the key in case the server needs to restart? Manually wouldn't be a goo choice. So you need to address this, too. If the server hardware features a TPM chip (your manual will tell you), this can be solved.
With server 2012's Bitlocker version, there's even a solution without a TPM, called netunlock but that requires a lot more, so before advising, you should give feedback whether this sounds interesting.
0
 

Author Comment

by:john80988
ID: 38854840
i think there is no way to prevent it, if user able to physical contact the server.
0
 
LVL 55

Expert Comment

by:McKnife
ID: 38858304
Now what should that mean? I showed you there is. He cannot go in when encrypted nor can he do offline attacks.
0
 
LVL 55

Expert Comment

by:McKnife
ID: 39159783
So how will proceed with this? No encryption? That's the wrong way. Encryption is the only possible way to protect against physical access?
0

Featured Post

Get 15 Days FREE Full-Featured Trial

Benefit from a mission critical IT monitoring with Monitis Premium or get it FREE for your entry level monitoring needs.
-Over 200,000 users
-More than 300,000 websites monitored
-Used in 197 countries
-Recommended by 98% of users

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

The recent Microsoft changes on update philosophy for Windows pre-10 and their impact on existing WSUS implementations.
I was prompted to write this article after the recent World-Wide Ransomware outbreak. For years now, System Administrators around the world have used the excuse of "Waiting a Bit" before applying Security Patch Updates. This type of reasoning to me …
This tutorial will walk an individual through the process of installing the necessary services and then configuring a Windows Server 2012 system as an iSCSI target. To install the necessary roles, go to Server Manager, and select Add Roles and Featu…
This tutorial will show how to configure a single USB drive with a separate folder for each day of the week. This will allow each of the backups to be kept separate preventing the previous day’s backup from being overwritten. The USB drive must be s…

627 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question