We view local user accounts on workstations and member servers as security risks. Can we disable the local accounts feature and force all our server and workstation administrators to use domain accounts?
Local accounts can expose you to additional risk for several reasons. Local accounts can't use Kerberos and must rely on the Windows NT LAN Manager (NTLM) authentication protocol, which is much easier to sniff and crack. And although local accounts are subject to the centralize...