Improve company productivity with a Business Account.Sign Up

x
?
Solved

tools to change automaticly local administrator password on all server and computer in my active directory domain

Posted on 2015-02-23
4
Medium Priority
?
65 Views
Last Modified: 2015-06-02
hello,

i need a tools to change automaticly local administrator for all windows servers and windows 7 computer every 6 month.

i have test GPO but its not secure.

thanks for help
0
Comment
Question by:cawasaki
  • 2
  • 2
4 Comments
 
LVL 31

Accepted Solution

by:
Rich Weissler earned 2000 total points
ID: 40625693
I attended a week of GCWN training last summer, and the instructor demonstrated a secure solution to this problem using powershell.  The complete solution is posted on his blog.
0
 
LVL 59

Expert Comment

by:McKnife
ID: 40626916
It is not the best idea to activate that account, security-wise. And when it's deactivated, the password may be empty, it simply does not matter. I would not recommend doing anything with that account, including password changing.
0
 
LVL 31

Expert Comment

by:Rich Weissler
ID: 40807988
Additional information because it came up recently  -- Microsoft "Local Administrator Password Solution" (LAPS) was recently released as version 6, and changes the local admin password more frequently, and stores the information in a protected location in the directory.
0
 
LVL 59

Expert Comment

by:McKnife
ID: 40808021
In my article http://www.experts-exchange.com/articles/18180/A-concept-for-safe-user-support.html I outline a concept superior to LAPS, suitable for end user support.
0

Featured Post

Building an Effective Phishing Protection Program

Join Director of Product Management Todd OBoyle on April 26th as he covers the key elements of a phishing protection program. Whether you’re an old hat at phishing education or considering starting a program -- we'll discuss critical components that should be in any program.

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

High user turnover can cause old/redundant user data to consume valuable space. UserResourceCleanup was developed to address this by automatically deleting user folders when the user account is deleted.
Native ability to set a user account password via AD GPO was removed because the passwords can be easily decrypted by any authenticated user in the domain. Microsoft recommends LAPS as a replacement and I have written an article that does something …
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…
Sometimes it takes a new vantage point, apart from our everyday security practices, to truly see our Active Directory (AD) vulnerabilities. We get used to implementing the same techniques and checking the same areas for a breach. This pattern can re…

585 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question