Disabling Local Administrators through GPO on Server 2008
ID: e0a40541-26e0-5c43-97d4-f36b89c69684
STIX ID: report--e0a40541-26e0-5c43-97d4-f36b89c69684
Feed Name: TrustedSec blog
This report explains a Group Policy Preferences scheduled-task technique to disable the built-in local Administrator account across Windows systems (including Server 2008/2003, Windows 7/Vista) after renaming the account, framed as a practice used during penetration tests to reduce reliance on local admin credentials.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
