๐ Secure Bits ๐ก
๐๐ถ๐ฑ ๐๐ผ๐ ๐ธ๐ป๐ผ๐ ๐๐ต๐ฒ ๐๐ผ๐ฐ๐ฎ๐น ๐๐ฑ๐บ๐ถ๐ป๐ถ๐๐๐ฟ๐ฎ๐๐ผ๐ฟ ๐ฎ๐ฐ๐ฐ๐ผ๐๐ป๐ ๐ฐ๐ฎ๐ป ๐ด๐ฒ๐ ๐น๐ผ๐ฐ๐ธ๐ฒ๐ฑ ๐ผ๐๐?
For years, the built-in local admin account couldnโt be locked outโattackers loved this loophole.
๐๐๐ ๐๐ต๐ถ๐ป๐ด๐ ๐ต๐ฎ๐๐ฒ ๐ฐ๐ต๐ฎ๐ป๐ด๐ฒ๐ฑ:
โ
Since 2022, thereโs a GPO to control this behavior.
โ
In Windows Server 2025, the default is that the built-in local admin can be locked out.
๐ช๐ต๐ ๐ฑ๐ผ๐ฒ๐ ๐๐ต๐ถ๐ ๐บ๐ฎ๐๐๐ฒ๐ฟ?
Because the local admin password is often:
โ Simple and weak
โ Shared across many servers
Attackers exploit this to move laterally without touching domain accounts.
Lockouts help stop brute-force attacksโbut keep in mind:
โ ๐ง๐ต๐ถ๐ ๐ผ๐ป๐น๐ ๐ฎ๐ฝ๐ฝ๐น๐ถ๐ฒ๐ ๐๐ผ ๐ป๐ฒ๐๐๐ผ๐ฟ๐ธ ๐น๐ผ๐ด๐ผ๐ป๐, not console logons.
Also, I hope youโre not using the same password across all servers!
If you are โ ๐๐๐ฎ๐ฟ๐ ๐๐๐ถ๐ป๐ด ๐๐๐ฃ๐ฆ (Local Administrator Password Solution) to rotate and manage local admin passwords securelyโthis was here long before 2022 as a protection for the same scenario.
๐ Did you know about this change?
