🔒 Secure Bits 💡
𝗔𝗿𝗲 𝘆𝗼𝘂 𝘀𝘁𝗶𝗹𝗹 𝘂𝘀𝗶𝗻𝗴 𝗔𝗗𝗔𝗱𝗺𝗶𝗻𝗶𝘀𝘁𝗿𝗮𝘁𝗼𝗿?
Just don’t. Really → don’t.
I still see this account used in production way too often, and it’s one of those “small” habits that turns into a big security problem (especially when the 𝗽𝗮𝘀𝘀𝘄𝗼𝗿𝗱 𝗵𝗮𝘀𝗻’𝘁 𝗰𝗵𝗮𝗻𝗴𝗲𝗱 since the 2000s…).
𝗪𝗵𝗮𝘁 𝘁𝗼 𝗱𝗼 with the built-in Administrator account:
🚫 𝗗𝗼𝗻’𝘁𝘀
▪️ Don’t use it after the initial AD installation is done
▪️ Don’t disable it (Microsoft DR guidance expects it to exist, so this one depends on your DR)
▪️ Don’t rename it – the SID stays the same, and in practice it usually creates more confusion for admins than for attackers.
▪️ And yes… don’t use it!
✅ 𝗗𝗼
▪️ Create a separate Tier 0 admin account with your name
▪️ Set Account is sensitive and cannot be delegated
▪️ Set a long, complex password
▪️ Store that password in a secure location (physical safe is fine)
▪️ Document the intended state and purpose
▪️ Then forget it exists and treat it as break-glass / DR only
That’s it. 𝗦𝗶𝗺𝗽𝗹𝗲.
💬 What’s your setup? Do you still see ADAdministrator being used day-to-day in your environment?
