Remedy: |
Rename the Administrator account, create a new Administrator account with only Guest access, remove network access for administrator, and monitor against logon attempts.
To rename the Administrator account, follow these steps:
- Open User Manager. From the Windows NT Start menu, select Programs, Administrative Tools (Common), User Manager.
- Select the Administrator account from the list.
- From the User menu, select Rename to display the Rename dialog box.
- In the Change to field, type the new name of the Administrator account and click OK.
—AND—
To create a new Administrator account:
- Open User Manager. From the Windows NT Start menu, select Programs, Administrative Tools (Common), User Manager.
- From the User menu, select New User to display the New User dialog box.
- In the Username field, type a new user named Administrator.
- In the Password field, type a new password for the Administrator account.
- In the Confirm Password field, confirm the new password.
- Click Groups to display the Group Memberships dialog box.
- Verify Administrator is only a member of the Guest group.
- Click OK twice to close both the Group Memberships and New User dialog boxes.
—AND—
To remove network access for Administrator, follow these steps:
- Open User Manager. From the Windows NT Start menu, select Programs, Administrative Tools (Common), User Manager.
- Select the Guest account from the list.
- From the Policies menu, select User Rights to display the User Rights Policy dialog box.
- From the Right list, select Access this computer from network.
- From the Grant to list, select the user account and click Remove.
- Click OK.
—AND—
To enable auditing for logon attempts, follow these steps:
- Open User Manager. From the Windows NT Start menu, select Programs, Administrative Tools (Common), User Manager.
- From the Policies menu, select Audit to display the Audit Policy dialog box.
- Select Audit these events. The audit choices are enabled.
- From the Logon and Logoff field, select the Failure check box or the Success check box.
- Click OK.
- Open the Event Viewer. From the Windows NT Start menu, select Programs, Administrative Tools (Common), Event Viewer.
- From the Log menu, select Security.
- Carefully monitor attempts to log in as Administrator.
|