Monday, May 19, 2008

GPO Preferences - Rename Local Administrator

Our GPO Preferences deployment has been largely completed, with over 85% of our systems now running the client side extensions. One of our first uses of the new settings is to rename the Local Admin account on all workstations and servers. One thing I discovered during testing is that you can use system variables for naming the local admin account:



So you can name your local admin account %ComputerName%_Bob and each machine will have a unique local admin account that is easy to remember but unique enough to block a bot style worm even if your local admin password is compromised.