Unsolved
This post is more than 5 years old
7 Posts
0
8625
December 20th, 2004 15:00
Can I safely change built-in administrator password?
I have a single Dimension 8300 with Windows XP Professional with SP 2 installed, using DSL internet connection but NOT running on a domain, and using Norton Internet Security. My built-in administrator account password is blank. I have 2 password protected User accounts with administrative privileges and the Guest User account is enabled. Reviewing Dell Community Forum shows this to be BAD security. I learned from the Forum to double press ctrl+alt+del while on the Windows logon screen to bring up the logon dialog box. Entering “administrator” (without the quotes) and leaving the password blank logged me on to the built-in administrator account. Then the User Account Control Panel revealed the administrator account.
I hesitate to change my administrator account password to a non-blank password and then reduce the user accounts to the Power User level because of the Forum warnings that I could lose data by doing this.
Is it safe to follow this procedure? If not, is there a safer way to introduce a non-blank password to the built-in administrator account? I have a password reset disc.


Denny Denham
2 Intern
•
18.8K Posts
0
December 20th, 2004 18:00
It is not only safe to change that password, it is recommended. See this. Changing the existing administrator accounts to limited accounts will not result in any loss of data, but Windows requires at least one administrator account in addition to the System Administrator. If you wish to operate normally using a limited account you should consider changing one of the two existing administrator to a limited account and then establishing another limited account for use by the person who also has access to the remaining administrator account.
nutcake
7 Posts
0
December 20th, 2004 21:00
Thank you Denny. The tech advice I got from support was all too complicated to be logical, revolved around forgotten passwords, and the password reset disc. Even to a suggestion to reformat my hard drive and start again. That is a nightmare! YOU TALK COMMON SENSE.
An appreciative nutcake
nutcake
7 Posts
0
December 21st, 2004 12:00
Denny Denham
2 Intern
•
18.8K Posts
0
December 21st, 2004 15:00
The reason my site recommends changing the password is that in the event the default (blank) password is not the one on the system a user who needs to make repairs to the system will be unable to access Recovery Console. The blank password does represent a security problem in that it allows anyone to log on to the computer and make changes to it, but if your computer is not available to anyone who might do this (such as in an office setting or a college dorm room) the security risk is minimal and you may decide that it isn't worth troubling with.
nutcake
7 Posts
0
December 21st, 2004 17:00
Thanks Denny. My teenage grandson is about to descend on me. He sleeps in the computer room. I want to provide access through GUEST. He may be saavy enough to use my built-in administrator logon. He has been known to travel the dark side of the internet and has repeatedly destroyed my daughter's PC such that it takes Geeks many moons to correct. I am trying to protect my PC against him. Is my procedure safe or must I use yours to change my default administrator password? If I do will that new password work? Should I take my chances with the internet troll?
JRosenfeld
2 Intern
•
4.4K Posts
0
December 21st, 2004 20:00
Libra1
197 Posts
0
December 22nd, 2004 03:00
Thank you.
Sincerely, Libra
Denny Denham
2 Intern
•
18.8K Posts
0
December 22nd, 2004 04:00
Yes, you can log on as the system administrator by pressing Ctrl-Alt-Delete twice in Normal Mode in XP Professional. It does not appear on the Welcome screen after you have logged on in that account, although there is a procedure which can add it to the Welcome screen. The security point is that the default password is blank and unless it is changed anyone (including an irresponsible relative) can obtain access to the entire system by simply opening that login screen and leaving the password blank. Since the fact that the default is a blank is well known, this can represent a severe breach of security.
Denny Denham
2 Intern
•
18.8K Posts
0
December 24th, 2004 00:00
That setting applies to all users, but you have the option if you wish of leaving the Limited accounts with a blank password so all they have to do is press to log on.
Libra1
197 Posts
0
December 24th, 2004 00:00
Sincerely, Libra
Libra1
197 Posts
0
December 24th, 2004 19:00
Sincerely, Libra