To protect the actual administrator account and let them hack away at a useless
account. Some will say it does not matter because there are ways to find the true
administrator account. That is not always the case such as when you have port 3389
open for Terminal Services. --- Steve
That is a good thing to do, but if someone has the proper tools they will
be able to see that the account is not the built in administrator account.
Even if the Administrator account is renamed it still retains its well
known SID.
- SID: S-1-5-<domain>-500 Name: Administrator Description: A user
account for the system administrator. By default, it is the only user
account that is given full control over the system.
Restrict anonymous settings are one way to possibly mitigate this type of
attack.
IBTerry [MSFT]
This posting is provided "AS IS" with no warranties, and confers no rights.
Ask a Question
Want to reply to this thread or ask your own question?
You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.