Unsolved

This post is more than 5 years old

7 Posts

8625

December 20th, 2004 15:00

Can I safely change built-in administrator password?

I have a single Dimension 8300 with Windows XP Professional with SP 2 installed, using DSL internet connection but NOT running on a domain, and using Norton Internet Security.  My built-in administrator account password is blank.  I have 2 password protected User accounts with administrative privileges and the Guest User account is enabled.  Reviewing Dell Community Forum shows this to be BAD security.  I learned from the Forum to double press ctrl+alt+del while on the Windows logon screen to bring up the logon dialog box.  Entering “administrator” (without the quotes) and leaving the password blank logged me on to the built-in administrator account.  Then the User Account Control Panel revealed the administrator account.

 

I hesitate to change my administrator account password to a non-blank password and then reduce the user accounts to the Power User level because of the Forum warnings that I could lose data by doing this.

 

Is it safe to follow this procedure?  If not, is there a safer way to introduce a non-blank password to the built-in administrator account?  I have a password reset disc.

2 Intern

 • 

18.8K Posts

December 20th, 2004 18:00

nutcake,

It is not only safe to change that password, it is recommended. See this. Changing the existing administrator accounts to limited accounts will not result in any loss of data, but Windows requires at least one administrator account in addition to the System Administrator. If you wish to operate normally using a limited account you should consider changing one of the two existing administrator to a limited account and then establishing another limited account for use by the person who also has access to the remaining administrator account.

7 Posts

December 20th, 2004 21:00

Thank you Denny.  The tech advice I got from support was all too complicated to be logical, revolved around forgotten passwords, and the password reset disc.  Even to a suggestion to reformat my hard drive and start again.  That is a nightmare!  YOU TALK COMMON SENSE.

An appreciative nutcake

7 Posts

December 21st, 2004 12:00

I read the links you provided and understand the suggested procedure.  My administrator password is not corrupted and I can logon to the built-in administrator which I think you refer to as the system administrator (I am just learning the terms).  This allows me to go to the User Account Control Panel, select the visible administrator icon, and change its password.  Is this dangerous?  Is the procedure outlined in your "This" link safer?  I am paranoid about messing with the registry or disturbing the incredibly complex operating system.  I know I seem over cautious.  I like to look before I leap.

2 Intern

 • 

18.8K Posts

December 21st, 2004 15:00

nutcake,

The reason my site recommends changing the password is that in the event the default (blank) password is not the one on the system a user who needs to make repairs to the system will be unable to access Recovery Console. The blank password does represent a security problem in that it allows anyone to log on to the computer and make changes to it, but if your computer is not available to anyone who might do this (such as in an office setting or a college dorm room) the security risk is minimal and you may decide that it isn't worth troubling with.

7 Posts

December 21st, 2004 17:00

Thanks Denny.  My teenage grandson is about to descend on me.  He sleeps in the computer room.  I want to provide access through GUEST.  He may be saavy enough to use my built-in administrator logon.  He has been known to travel the dark side of the internet and has repeatedly destroyed my daughter's PC such that it takes Geeks many moons to correct.  I am trying to protect my PC against him.  Is my procedure safe or must I use yours to change my default administrator password?  If I do will that new password work?  Should I take my chances with the internet troll?

2 Intern

 • 

4.4K Posts

December 21st, 2004 20:00

If you follw Denny's instructions you'll be OK. You can always set it back to blank (i.e. no password) once the dangerous guest has departed :-).

197 Posts

December 22nd, 2004 03:00

I have some questions about this. In XP Pro can you access the SYSTEM ADMIN account by just using c/a/d twice at the Windows log-on screen? (That seems to be what Nutcase is saying.) Does it appear as a log-on in regular Windows after that? And if you can access it by c/a/d and not typing in a password, wouldn't you still be able to access SYSTEM ADMIN with a blank password if you had to use it?
Thank you.
Sincerely, Libra

2 Intern

 • 

18.8K Posts

December 22nd, 2004 04:00

Libra1,

Yes, you can log on as the system administrator by pressing Ctrl-Alt-Delete twice in Normal Mode in XP Professional. It does not appear on the Welcome screen after you have logged on in that account, although there is a procedure which can add it to the Welcome screen. The security point is that the default password is blank and unless it is changed anyone (including an irresponsible relative) can obtain access to the entire system by simply opening that login screen and leaving the password blank. Since the fact that the default is a blank is well known, this can represent a severe breach of security.

2 Intern

 • 

18.8K Posts

December 24th, 2004 00:00

Libra1,

That setting applies to all users, but you have the option if you wish of leaving the Limited accounts with a blank password so all they have to do is press to log on.

197 Posts

December 24th, 2004 00:00

Thank you Denny for explaining the security breach in leaving it blank. When you check "Users must enter a user name and password to use this computer" does that apply to limited users too? I might want to set a password for the System Admin account, but I don't want the limited users to have to use a password.

Sincerely, Libra

197 Posts

December 24th, 2004 19:00

Thanks Denny.
Sincerely, Libra
No Events found!

Top