?
Solved

How can I prevent Offline NT from being able to access the SAM hive without encrypting?

Posted on 2014-12-09
4
Medium Priority
?
95 Views
Last Modified: 2014-12-15
I'm concerned that a PC that is in a high risk area may be "lost" or stolen and want to ensure that non-default administrator account cannot be accessed.
0
Comment
Question by:flipm0
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
4 Comments
 
LVL 37

Accepted Solution

by:
Neil Russell earned 1500 total points
ID: 40489864
If the machine is in an insecure area and has sensitive information on it then I would start by enforcing some kind of FULL DISK ENCRYPTION.

Not often I quote WiKipedia but in this instance its a good source for a whole lot of list all about your options.
http://en.wikipedia.org/wiki/Comparison_of_disk_encryption_software

At least then you know that nobody can access ANYTHING once it is off without your encryption password.
0
 
LVL 12

Expert Comment

by:Sommerblink
ID: 40489964
Without full-disk encryption, there is no way to prevent someone who has physical access to a computer with unlimited time from breaking into the computer.

Without whole-disk encryption, it is a trivial matter to do a cd/dvd 'rescue disk' and wipe out the passwords on all existing accounts in the SAM database.

Without whole-disk encryption, it is a trivial matter to remove the hard drive from the stolen computer and attach it to another Windows computer and mount the drive through there (or another OS that understands NTFS). All prior NTFS permissions protecting the data become moot.
0
 
LVL 15

Expert Comment

by:Giovanni Heward
ID: 40490146
You're going to need either physical or logical controls (e.g. encryption), or both.  If you can lock the device in a cabinet, that may be the most practical solution for your scenario.
0
 
LVL 96

Expert Comment

by:Lee W, MVP
ID: 40490185
I agree with everyone above - without encryption, your only as secure as you can physically make the server.

That said, WHY don't you want encryption?
0

Featured Post

Complete VMware vSphere® ESX(i) & Hyper-V Backup

Capture your entire system, including the host, with patented disk imaging integrated with VMware VADP / Microsoft VSS and RCT. RTOs is as low as 15 seconds with Acronis Active Restore™. You can enjoy unlimited P2V/V2V migrations from any source (even from a different hypervisor)

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

By default the complete memory dump option is disabled in windows . If we want to enable the complete memory dump for a diagnostic purpose, we have a solution for it. here we are using the registry method to enable this.
The Windows functions GetTickCount and timeGetTime retrieve the number of milliseconds since the system was started. However, the value is stored in a DWORD, which means that it wraps around to zero every 49.7 days. This article shows how to solve t…
In this video, we discuss why the need for additional vertical screen space has become more important in recent years, namely, due to the transition in the marketplace of 4x3 computer screens to 16x9 and 16x10 screens (so-called widescreen format). …
The viewer will learn how to successfully create a multiboot device using the SARDU utility on Windows 7. Start the SARDU utility: Change the image directory to wherever you store your ISOs, this will prevent you from having 2 copies of an ISO wit…
Suggested Courses
Course of the Month11 days, 9 hours left to enroll

752 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question