ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    Is it possibe to remove local admin on Windows Server?

    IT Discussion
    6
    15
    347
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • 1
      1337
      last edited by 1337

      It possible to completely remove the local admin account on Windows Server that belongs to a domain? Or prevent logins.

      Or is always possible to login as local admin (if you know the name/passwd)?

      WLS-ITGuyW 1 Reply Last reply Reply Quote 0
      • WLS-ITGuyW
        WLS-ITGuy @1337
        last edited by

        @Pete-S

        As long as the server isn't a DC you can disable the local admin account. Just make your domain admin, or an account with domain admin rights, part of the local admin group.

        1 1 Reply Last reply Reply Quote 1
        • 1
          1337 @WLS-ITGuy
          last edited by

          @WLS-ITGuy said in Is it possibe to remove local admin on Windows Server?:

          @Pete-S

          As long as the server isn't a DC you can disable the local admin account. Just make your domain admin, or an account with domain admin rights, part of the local admin group.

          OK, thanks!

          1 Reply Last reply Reply Quote 0
          • GreyG
            Grey
            last edited by

            A better solution: https://www.microsoft.com/en-us/download/details.aspx?id=46899

            WLS-ITGuyW 1 Reply Last reply Reply Quote 2
            • WLS-ITGuyW
              WLS-ITGuy @Grey
              last edited by

              @Grey said in Is it possibe to remove local admin on Windows Server?:

              A better solution: https://www.microsoft.com/en-us/download/details.aspx?id=46899

              Definitely a better option.

              1 1 Reply Last reply Reply Quote 0
              • 1
                1337 @WLS-ITGuy
                last edited by

                @WLS-ITGuy said in Is it possibe to remove local admin on Windows Server?:

                @Grey said in Is it possibe to remove local admin on Windows Server?:

                A better solution: https://www.microsoft.com/en-us/download/details.aspx?id=46899

                Definitely a better option.

                Ah, so it sets a unique password for local admin on every server and saves those password in the AD so people can find out what the password is?

                GreyG 1 Reply Last reply Reply Quote 0
                • dbeatoD
                  dbeato
                  last edited by

                  @Pete-S said in Is it possibe to remove local admin on Windows Server?:

                  ve the local admin account on Windows Server that belongs to a domain? Or prevent logins.
                  Or is always possible to login as local admin (if you know the name/passwd)?

                  I wouldn't disable the local admin of a server, it would come handy if you need to restore stuff or remove and add from the domain. LAPS works but beware 🙂

                  pmonchoP 1 Reply Last reply Reply Quote 1
                  • pmonchoP
                    pmoncho @dbeato
                    last edited by

                    @dbeato said in Is it possibe to remove local admin on Windows Server?:

                    @Pete-S said in Is it possibe to remove local admin on Windows Server?:

                    ve the local admin account on Windows Server that belongs to a domain? Or prevent logins.
                    Or is always possible to login as local admin (if you know the name/passwd)?

                    I wouldn't disable the local admin of a server, it would come handy if you need to restore stuff or remove and add from the domain. LAPS works but beware 🙂

                    I agree with @dbeato. When sh$% hits the fan with the server, no networking or no cached credentials, you will long for a local admin account.

                    I do disable the Administrator account after creating my own local admin with 20+ char strong password. Less worries on both the security and DR front.

                    GreyG 1 Reply Last reply Reply Quote 1
                    • GreyG
                      Grey @1337
                      last edited by

                      @Pete-S said in Is it possibe to remove local admin on Windows Server?:

                      @WLS-ITGuy said in Is it possibe to remove local admin on Windows Server?:

                      @Grey said in Is it possibe to remove local admin on Windows Server?:

                      A better solution: https://www.microsoft.com/en-us/download/details.aspx?id=46899

                      Definitely a better option.

                      Ah, so it sets a unique password for local admin on every server and saves those password in the AD so people can find out what the password is?

                      Correct.

                      1 Reply Last reply Reply Quote 0
                      • GreyG
                        Grey @pmoncho
                        last edited by

                        @pmoncho said in Is it possibe to remove local admin on Windows Server?:

                        @dbeato said in Is it possibe to remove local admin on Windows Server?:

                        @Pete-S said in Is it possibe to remove local admin on Windows Server?:

                        ve the local admin account on Windows Server that belongs to a domain? Or prevent logins.
                        Or is always possible to login as local admin (if you know the name/passwd)?

                        I wouldn't disable the local admin of a server, it would come handy if you need to restore stuff or remove and add from the domain. LAPS works but beware 🙂

                        I agree with @dbeato. When sh$% hits the fan with the server, no networking or no cached credentials, you will long for a local admin account.

                        I do disable the Administrator account after creating my own local admin with 20+ char strong password. Less worries on both the security and DR front.

                        Yes, but if you have physical or kvm access, even virtual, you can use linux ntpass to turn on the admin account and reset the password. This would be the last resort if you really lost the admin access, which is rare.

                        dbeatoD 1 Reply Last reply Reply Quote 0
                        • dbeatoD
                          dbeato @Grey
                          last edited by

                          @Grey said in Is it possibe to remove local admin on Windows Server?:

                          @pmoncho said in Is it possibe to remove local admin on Windows Server?:

                          @dbeato said in Is it possibe to remove local admin on Windows Server?:

                          @Pete-S said in Is it possibe to remove local admin on Windows Server?:

                          ve the local admin account on Windows Server that belongs to a domain? Or prevent logins.
                          Or is always possible to login as local admin (if you know the name/passwd)?

                          I wouldn't disable the local admin of a server, it would come handy if you need to restore stuff or remove and add from the domain. LAPS works but beware 🙂

                          I agree with @dbeato. When sh$% hits the fan with the server, no networking or no cached credentials, you will long for a local admin account.

                          I do disable the Administrator account after creating my own local admin with 20+ char strong password. Less worries on both the security and DR front.

                          Yes, but if you have physical or kvm access, even virtual, you can use linux ntpass to turn on the admin account and reset the password. This would be the last resort if you really lost the admin access, which is rare.

                          Not since UEFI... At least it doesn't work with Windows 10 and subsequent kernels.

                          GreyG 1 Reply Last reply Reply Quote 1
                          • GreyG
                            Grey @dbeato
                            last edited by

                            @dbeato said in Is it possibe to remove local admin on Windows Server?:

                            @Grey said in Is it possibe to remove local admin on Windows Server?:

                            @pmoncho said in Is it possibe to remove local admin on Windows Server?:

                            @dbeato said in Is it possibe to remove local admin on Windows Server?:

                            @Pete-S said in Is it possibe to remove local admin on Windows Server?:

                            ve the local admin account on Windows Server that belongs to a domain? Or prevent logins.
                            Or is always possible to login as local admin (if you know the name/passwd)?

                            I wouldn't disable the local admin of a server, it would come handy if you need to restore stuff or remove and add from the domain. LAPS works but beware 🙂

                            I agree with @dbeato. When sh$% hits the fan with the server, no networking or no cached credentials, you will long for a local admin account.

                            I do disable the Administrator account after creating my own local admin with 20+ char strong password. Less worries on both the security and DR front.

                            Yes, but if you have physical or kvm access, even virtual, you can use linux ntpass to turn on the admin account and reset the password. This would be the last resort if you really lost the admin access, which is rare.

                            Not since UEFI... At least it doesn't work with Windows 10 and subsequent kernels.

                            I can imagine you had problems because of bitlocker or something similar, but not UEFI, unless the system was locked out to only boot a certain way through config. Maybe you could test a UEFI boot with a Hiren's USB boot just for fun?

                            dbeatoD 1 Reply Last reply Reply Quote 1
                            • dbeatoD
                              dbeato @Grey
                              last edited by

                              @Grey said in Is it possibe to remove local admin on Windows Server?:

                              @dbeato said in Is it possibe to remove local admin on Windows Server?:

                              @Grey said in Is it possibe to remove local admin on Windows Server?:

                              @pmoncho said in Is it possibe to remove local admin on Windows Server?:

                              @dbeato said in Is it possibe to remove local admin on Windows Server?:

                              @Pete-S said in Is it possibe to remove local admin on Windows Server?:

                              ve the local admin account on Windows Server that belongs to a domain? Or prevent logins.
                              Or is always possible to login as local admin (if you know the name/passwd)?

                              I wouldn't disable the local admin of a server, it would come handy if you need to restore stuff or remove and add from the domain. LAPS works but beware 🙂

                              I agree with @dbeato. When sh$% hits the fan with the server, no networking or no cached credentials, you will long for a local admin account.

                              I do disable the Administrator account after creating my own local admin with 20+ char strong password. Less worries on both the security and DR front.

                              Yes, but if you have physical or kvm access, even virtual, you can use linux ntpass to turn on the admin account and reset the password. This would be the last resort if you really lost the admin access, which is rare.

                              Not since UEFI... At least it doesn't work with Windows 10 and subsequent kernels.

                              I can imagine you had problems because of bitlocker or something similar, but not UEFI, unless the system was locked out to only boot a certain way through config. Maybe you could test a UEFI boot with a Hiren's USB boot just for fun?

                              I have tried with the latest Hiren's Boot drive and still doesn't work for Windows 10 for some reason in UEFI... Even if it was bitlocker I could always decrypt and then use it if worked properly. At least the old ntpasswd didn't work (this one https://pogostick.net/~pnh/ntpasswd/) With WIndows 10. Just for giggles I will try it on a VM today with this https://www.hirensbootcd.org/howtos/

                              black3dynamiteB 1 Reply Last reply Reply Quote 0
                              • black3dynamiteB
                                black3dynamite @dbeato
                                last edited by

                                @dbeato said in Is it possibe to remove local admin on Windows Server?:

                                @Grey said in Is it possibe to remove local admin on Windows Server?:

                                @dbeato said in Is it possibe to remove local admin on Windows Server?:

                                @Grey said in Is it possibe to remove local admin on Windows Server?:

                                @pmoncho said in Is it possibe to remove local admin on Windows Server?:

                                @dbeato said in Is it possibe to remove local admin on Windows Server?:

                                @Pete-S said in Is it possibe to remove local admin on Windows Server?:

                                ve the local admin account on Windows Server that belongs to a domain? Or prevent logins.
                                Or is always possible to login as local admin (if you know the name/passwd)?

                                I wouldn't disable the local admin of a server, it would come handy if you need to restore stuff or remove and add from the domain. LAPS works but beware 🙂

                                I agree with @dbeato. When sh$% hits the fan with the server, no networking or no cached credentials, you will long for a local admin account.

                                I do disable the Administrator account after creating my own local admin with 20+ char strong password. Less worries on both the security and DR front.

                                Yes, but if you have physical or kvm access, even virtual, you can use linux ntpass to turn on the admin account and reset the password. This would be the last resort if you really lost the admin access, which is rare.

                                Not since UEFI... At least it doesn't work with Windows 10 and subsequent kernels.

                                I can imagine you had problems because of bitlocker or something similar, but not UEFI, unless the system was locked out to only boot a certain way through config. Maybe you could test a UEFI boot with a Hiren's USB boot just for fun?

                                I have tried with the latest Hiren's Boot drive and still doesn't work for Windows 10 for some reason in UEFI... Even if it was bitlocker I could always decrypt and then use it if worked properly. At least the old ntpasswd didn't work (this one https://pogostick.net/~pnh/ntpasswd/) With WIndows 10. Just for giggles I will try it on a VM today with this https://www.hirensbootcd.org/howtos/

                                You just use Ubuntu, enable the repo that provides chntpw package to make changes to Windows accounts?

                                dbeatoD 1 Reply Last reply Reply Quote 0
                                • dbeatoD
                                  dbeato @black3dynamite
                                  last edited by

                                  @black3dynamite said in Is it possibe to remove local admin on Windows Server?:

                                  @dbeato said in Is it possibe to remove local admin on Windows Server?:

                                  @Grey said in Is it possibe to remove local admin on Windows Server?:

                                  @dbeato said in Is it possibe to remove local admin on Windows Server?:

                                  @Grey said in Is it possibe to remove local admin on Windows Server?:

                                  @pmoncho said in Is it possibe to remove local admin on Windows Server?:

                                  @dbeato said in Is it possibe to remove local admin on Windows Server?:

                                  @Pete-S said in Is it possibe to remove local admin on Windows Server?:

                                  ve the local admin account on Windows Server that belongs to a domain? Or prevent logins.
                                  Or is always possible to login as local admin (if you know the name/passwd)?

                                  I wouldn't disable the local admin of a server, it would come handy if you need to restore stuff or remove and add from the domain. LAPS works but beware 🙂

                                  I agree with @dbeato. When sh$% hits the fan with the server, no networking or no cached credentials, you will long for a local admin account.

                                  I do disable the Administrator account after creating my own local admin with 20+ char strong password. Less worries on both the security and DR front.

                                  Yes, but if you have physical or kvm access, even virtual, you can use linux ntpass to turn on the admin account and reset the password. This would be the last resort if you really lost the admin access, which is rare.

                                  Not since UEFI... At least it doesn't work with Windows 10 and subsequent kernels.

                                  I can imagine you had problems because of bitlocker or something similar, but not UEFI, unless the system was locked out to only boot a certain way through config. Maybe you could test a UEFI boot with a Hiren's USB boot just for fun?

                                  I have tried with the latest Hiren's Boot drive and still doesn't work for Windows 10 for some reason in UEFI... Even if it was bitlocker I could always decrypt and then use it if worked properly. At least the old ntpasswd didn't work (this one https://pogostick.net/~pnh/ntpasswd/) With WIndows 10. Just for giggles I will try it on a VM today with this https://www.hirensbootcd.org/howtos/

                                  You just use Ubuntu, enable the repo that provides chntpw package to make changes to Windows accounts?

                                  Yeah, I have used that.

                                  1 Reply Last reply Reply Quote 0
                                  • 1 / 1
                                  • First post
                                    Last post