Windows Vista Forums
Vista Forums Home Join Vista Forums Windows 7 Forum Vista Tutorials Tags
Welcome to Windows Vista Forums. Our forum is dedicated to helping you find solutions with any problems, errors or issues you are experiencing with Windows Vista. The Vista forum also covers news and updates and has an extensive Windows Vista tutorial section that covers a wide range of tips and tricks.

Go Back   Vista Forums > Vista Newsgroups > Vista security

Vista - Encrypting Administrator's profile

Reply
 
Old 01-09-2009   #1 (permalink)
Kirsten


 
 

Encrypting Administrator's profile

Is there any way to encrypt (EFS or similar) the entire administrator's
profile folder (C:\Documents and Settings\Administrator) so as to prevent a
user from login in to the computer if he changes the password with a dos
utility? (CIA Commander for example).

There's no point in having domain policies if the user can login as the
administrator and do whetever he wants with the computer!

What else do you suggest? (please don't say "put a bios password" or "forbid
physical access to the computer")

Thanks a lot!




My System SpecsSystem Spec
Old 01-09-2009   #2 (permalink)
Shenan Stanley


 
 

Re: Encrypting Administrator's profile

Kirsten wrote:
Quote:

> Is there any way to encrypt (EFS or similar) the entire
> administrator's profile folder (C:\Documents and
> Settings\Administrator) so as to prevent a user from login in to
> the computer if he changes the password with a dos utility? (CIA
> Commander for example).
> There's no point in having domain policies if the user can login as
> the administrator and do whetever he wants with the computer!
>
> What else do you suggest? (please don't say "put a bios password"
> or "forbid physical access to the computer")
Why is this user able to logon as an administrative level account in the
first place?

--
Shenan Stanley
MS-MVP
--
How To Ask Questions The Smart Way
http://www.catb.org/~esr/faqs/smart-questions.html


My System SpecsSystem Spec
Old 01-09-2009   #3 (permalink)
Kirsten


 
 

Re: Encrypting Administrator's profile

He's not, but there are several utilities that easily disable the
administrator account.

"Shenan Stanley" <newshelper@xxxxxx> wrote in message
news:%23I7wn5mcJHA.2444@xxxxxx
Quote:

> Kirsten wrote:
Quote:

>> Is there any way to encrypt (EFS or similar) the entire
>> administrator's profile folder (C:\Documents and
>> Settings\Administrator) so as to prevent a user from login in to
>> the computer if he changes the password with a dos utility? (CIA
>> Commander for example).
>> There's no point in having domain policies if the user can login as
>> the administrator and do whetever he wants with the computer!
>>
>> What else do you suggest? (please don't say "put a bios password"
>> or "forbid physical access to the computer")
>
> Why is this user able to logon as an administrative level account in the
> first place?
>
> --
> Shenan Stanley
> MS-MVP
> --
> How To Ask Questions The Smart Way
> http://www.catb.org/~esr/faqs/smart-questions.html
>

My System SpecsSystem Spec
Old 01-09-2009   #4 (permalink)
Gordon


 
 

Re: Encrypting Administrator's profile

Kirsten wrote:
Quote:

> He's not, but there are several utilities that easily disable the
> administrator account.
>
Sounds like some discipline is in order. If this is a workplace, make it
a sackable offence to install or use any software not authorised by the
company. If a home environment, just deny physically, access to the
machine until the user learns to respect computer security.


--
Asking a question?
Please tell us the version of the application you are asking about,
your OS, Service Pack level
and the FULL contents of any error message(s)
My System SpecsSystem Spec
Old 01-09-2009   #5 (permalink)
Shenan Stanley


 
 

Re: Encrypting Administrator's profile

Kirsten wrote:
Quote:

> Is there any way to encrypt (EFS or similar) the entire
> administrator's profile folder (C:\Documents and
> Settings\Administrator) so as to prevent a user from login in to
> the computer if he changes the password with a dos utility? (CIA
> Commander for example).
> There's no point in having domain policies if the user can login as
> the administrator and do whetever he wants with the computer!
>
> What else do you suggest? (please don't say "put a bios password"
> or "forbid physical access to the computer")
Shenan Stanley wrote:
Quote:

> Why is this user able to logon as an administrative level account
> in the first place?
Kirsten wrote:
Quote:

> He's not, but there are several utilities that easily disable the
> administrator account.
Did you mean 'disable' or 'allow them to use' the administrator account?

You didn't want to hear it because you know it's true... "Physical access,
time and a little knowledge means anyone who sits at the machine basically
can own it..."

Are you protecting what's in the administrator account (should be much of
nothing) or is it you just don't want them using the account?

If the latter - your battle is lost before it was started. Encrypt all you
want - physical access can give the user another/the same administrative
account with a little effort and a few tools and time. Maybe not so much
the data in the profile - but there should be nothing in (files, etc) the
actual built-in administrator's account of importance anyway, IMO.

I think you need to divulge what it is you hope to accomplish in order to
better narrow the possible answers. What is the actual problem and need?

--
Shenan Stanley
MS-MVP
--
How To Ask Questions The Smart Way
http://www.catb.org/~esr/faqs/smart-questions.html


My System SpecsSystem Spec
Old 01-13-2009   #6 (permalink)
Mel K.


 
 

Re: Encrypting Administrator's profile

You can use a full disk encryption product to encrypt the entire hard drive.
FDE will prevent offline access to the hard drive, meaning you would not be
able to boot the computer into another OS and access the drive. Windows
Vista with BitLocker should do the trick. Vista SP1 made some improvements
to BitLocker.

--
Mel K.
MCSA: M

"Kirsten" <noreply@xxxxxx> wrote in message
news:OHXGxdkcJHA.4660@xxxxxx
Quote:

> Is there any way to encrypt (EFS or similar) the entire administrator's
> profile folder (C:\Documents and Settings\Administrator) so as to prevent
> a
> user from login in to the computer if he changes the password with a dos
> utility? (CIA Commander for example).
>
> There's no point in having domain policies if the user can login as the
> administrator and do whetever he wants with the computer!
>
> What else do you suggest? (please don't say "put a bios password" or
> "forbid
> physical access to the computer")
>
> Thanks a lot!
>
>
>

My System SpecsSystem Spec
Reply

Thread Tools


Similar Threads
Thread Forum
Administrator's Password Vista General
Windows cannot find the local profile and is logging you on with a temporary profile. Changes you make to this profile will be lost when you log off. Vista General
Moved Contacts to C:\Users over my profile and I have a copy of my profile under my profile in the explorer only. Vista file management
Re: Administrator's privileges Vista account administration
RE: Administrator's privileges Vista account administration


Vista Forums is an independent web site and has not been authorized,
sponsored, or otherwise approved by Microsoft Corporation.
"Windows Vista", the Start Orb, and related materials are trademarks of Microsoft Corp.
© Designer Media Ltd

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46