|
-
September 22nd, 2004, 12:07 AM
#19
We renamed the enterprise admin account a long time ago. Then applied a very random, long and complex password to it and locked it in a safe--just in case we have to recover the forest. Then we just don't use it. We really should change the password on this account periodically, though. However, we rename the thing again every now and then. Just to keep things interesting. We use two accounts. A personal one and an SA account. The personal is a normal account. The SA account is the one used to manage and make changes. Audit trail, you know.
Yeah, the security by obscurity thing is the only reason for changing the local admin, or domain admin account names. It just makes it harder to write scripts that attack normal admin account names. Smart scripters will use LDAP or other methods to use the SID, which doesn't change.
Your best bet is to create a good, long, complex password and then don't use the account, especially in a remote session.
Posting Permissions
- You may not post new threads
- You may not post replies
- You may not post attachments
- You may not edit your posts
-
Forum Rules
|
|