Solved

How can I prevent Offline NT from being able to access the SAM hive without encrypting?

Posted on 2014-12-09
4
78 Views
Last Modified: 2014-12-15
I'm concerned that a PC that is in a high risk area may be "lost" or stolen and want to ensure that non-default administrator account cannot be accessed.
0
Comment
Question by:flipm0
4 Comments
 
LVL 37

Accepted Solution

by:
Neil Russell earned 500 total points
ID: 40489864
If the machine is in an insecure area and has sensitive information on it then I would start by enforcing some kind of FULL DISK ENCRYPTION.

Not often I quote WiKipedia but in this instance its a good source for a whole lot of list all about your options.
http://en.wikipedia.org/wiki/Comparison_of_disk_encryption_software

At least then you know that nobody can access ANYTHING once it is off without your encryption password.
0
 
LVL 12

Expert Comment

by:Sommerblink
ID: 40489964
Without full-disk encryption, there is no way to prevent someone who has physical access to a computer with unlimited time from breaking into the computer.

Without whole-disk encryption, it is a trivial matter to do a cd/dvd 'rescue disk' and wipe out the passwords on all existing accounts in the SAM database.

Without whole-disk encryption, it is a trivial matter to remove the hard drive from the stolen computer and attach it to another Windows computer and mount the drive through there (or another OS that understands NTFS). All prior NTFS permissions protecting the data become moot.
0
 
LVL 14

Expert Comment

by:Giovanni Heward
ID: 40490146
You're going to need either physical or logical controls (e.g. encryption), or both.  If you can lock the device in a cabinet, that may be the most practical solution for your scenario.
0
 
LVL 95

Expert Comment

by:Lee W, MVP
ID: 40490185
I agree with everyone above - without encryption, your only as secure as you can physically make the server.

That said, WHY don't you want encryption?
0

Featured Post

Netscaler Common Configuration How To guides

If you use NetScaler you will want to see these guides. The NetScaler How To Guides show administrators how to get NetScaler up and configured by providing instructions for common scenarios and some not so common ones.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

So many times I have seen the words written in a question "if only I could show you" or " I know how hard it is for you since you can't see it" in any zone. That has inspired me to write about this tool in windows 7 called "Problem Steps Recorder…
A quick guide on how to use Group Policy to create a custom power plan and set it active on Windows 7.
Windows 8 comes with a dramatically different user interface known as Metro. Notably missing from the new interface is a Start button and Start Menu. Many users do not like it, much preferring the interface of earlier versions — Windows 7, Windows X…
This Micro Tutorial will give you a basic overview of Windows Live Photo Gallery and show you various editing filters and touches to photos you can apply. This will be demonstrated using Windows Live Photo Gallery on Windows 7 operating system.

947 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

18 Experts available now in Live!

Get 1:1 Help Now