Solved

GPO for administrator account

Posted on 2014-04-21
7
291 Views
Last Modified: 2014-06-12
Looking to create a vb script that will enable the built in administrator account (if disabled)
Rename it too – Admin
And set a password
(Windows 7)
Would like to do this via GPO, is there a vb script option to run at startup?

Thanks
0
Comment
Question by:kwatt562
  • 3
  • 2
  • 2
7 Comments
 
LVL 21

Expert Comment

by:Joseph Moody
Comment Utility
This can be done in Group Policy.

The enable and rename settings can be found under Computer Configuration/Window Settings/Security Settings/Local Policies/Security Options/Accounts.

You can set the password with Group Policy Preferences Local Users and Groups.
0
 

Author Comment

by:kwatt562
Comment Utility
The first part is OK, not sure how to set the password though as its 2003 server
0
 
LVL 21

Accepted Solution

by:
Joseph Moody earned 500 total points
Comment Utility
0
Threat Intelligence Starter Resources

Integrating threat intelligence can be challenging, and not all companies are ready. These resources can help you build awareness and prepare for defense.

 

Author Comment

by:kwatt562
Comment Utility
Cancel that I have found a 2008 R2 server :) will let you know how goes, thanks  alot
0
 
LVL 53

Expert Comment

by:McKnife
Comment Utility
It should be noted that using group policy preferences to set the password puts the whole lot of computers at risk because
A that password is the same everywhere
B it can be read out in plain text, so anyone with a little knowhow could own all your computers from now on if he liked to.
Read results here: https://www.google.com/search?q=gpp+password+security&sourceid=ie7&rls=com.microsoft:en-US:IE-Address&ie=&oe=
Please note that the link you were given contained that warning, too (at the very end).*

You should tell us why you need that account and what you use it for. Maybe we can tell you a better solution to achieve it.

*Just for laughs: the MVP (F. Frommherz) who in that linked article claimed we could not get our hands on a plaintext password changed his mind: http://www.frickelsoft.net/blog/?p=116

http://www.gruppenrichtlinien.de/artikel/verwaltungaenderung-der-lokalen-administratoren-kennworte/ is another tactical approach: set the pw, apply and delete the GPO afterwards so that it cannot be attacked in sysvol. Ha... that's history. Win8.1 uses GPO caching, it will have a local copy of that policy, so we have to be careful! Read http://4sysops.com/archives/group-policy-caching-in-windows-8-1/
0
 
LVL 53

Expert Comment

by:McKnife
Comment Utility
The solution is no solution, sorry. Simply, because it does not work anymore. Since the patch day of may 14, for security's sake, microsoft has disabled the ability to enclose passwords in account items in group policy preferences.
0
 
LVL 53

Expert Comment

by:McKnife
Comment Utility
So better look at the alternative described here: http://blogs.technet.com/b/askpfeplat/archive/2014/05/19/how-to-automate-changing-the-local-administrator-password.aspx - it holds all the background info to the change as well.
0

Featured Post

6 Surprising Benefits of Threat Intelligence

All sorts of threat intelligence is available on the web. Intelligence you can learn from, and use to anticipate and prepare for future attacks.

Join & Write a Comment

Suggested Solutions

This script will sweep a range of IP addresses (class c only, 255.255.255.0) and report to a log the version of office installed. What it does: 1.)      Creates log file in the directory the script is run from (if it doesn't already exist) 2.)      Sweep…
Not long ago I saw a question in the VB Script forum that I thought would not take much time. You can read that question (Question ID  (http://www.experts-exchange.com/Programming/Languages/Visual_Basic/VB_Script/Q_28455246.html)28455246) Here (http…
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…
This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …

772 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

15 Experts available now in Live!

Get 1:1 Help Now