Subscribe to Windows IT Pro

 

Get Newsletters

  • Get the Latest News
  • Product Updates
  • Helpful Tricks
  • Productivity Tips

Subscribe Now!

October 14, 2009 12:00 AM

Default Accounts and Groups – Security Principles

Windows IT Pro
InstantDoc ID #102978
Rating: (0)

Before creating an Access Control Entry (ACE) on an object, you need an account, group or other Security Identifier (SID) to ascertain to which security principle the ACE will apply. There have been some important changes to the built-in accounts and groups. The Administrator account is disabled by default in Windows Vista. It was often the case that the Administrator account password was the same on every workstation, which constituted a security risk. A disabled Administrator account will relieve administrators of the need to manage the account’s password on every workstation. If you get into trouble, the built-in Administrator account can still be used in Safe Mode and in the Recovery Console. In Windows Server 2008 and Vista, UAC does not apply to the built-in Administrator account. However unless configured otherwise, UAC applies to all new accounts that are members of the Administrators group.

The Power Users group still exists for the purposes of backwards compatibility, but has been depreciated. The rights which were granted to this group in previous versions of Windows have been removed. Remote Assistance has been redesigned so that the HelpAssistant account is no longer required. The Support_ account, which was used to execute Support Center scripts, has also gone.

New groups include: IIS_IUSRS, which performs the same function as the IUSR_ account on XP. Removing the component of the account name makes it easier to control this account using automated mechanisms such as Group Policy, as the name is the same across all machines; Event Log Readers, which can alleviate the need to modify Security Description Definition Language (SDDL) strings on event logs; Performance Log Users can schedule performance counter logging, enable trace providers, enumerate event traces locally and remotely, but monitoring system processes is still granted using the Profile system performance (SeSystemProfilePrivilege) privilege; Performance Monitor Users can access performance counter data; the Distributed COM Users group was originally added to Windows Server 2003 SP1 to provide an easy way to apply DCOM computer restriction settings to users; In Vista SP1 and Server 2008, the Cryptographic Operators group enables Cryptography API: Next Generation (CNG) support, giving access to features such as crypto settings in the IPSec policy of the Windows Firewall.

Related Content:

ARTICLE TOOLS

Comments
    There are no comments to display. Be the first one!
You must log on before posting a comment.

Are you a new visitor? Register Here

advertisement

advertisement

White Papers

Get your Windows 7 deployment off to the right start by implementing PC lockdown. A locked-down environment is easier and cheaper to support since users are less likely to make unnecessary changes to the core system configuration - read more here!

Essential Guides

Is your iSCSI "lossy"? The reality is that most off-the-shelf Ethernet hardware deployed for iSCSI can lose packets, resulting in slow performance or application downtime. Learn how to assess your current iSCSI infrastructure and engineer an advanced iSCSI SAN infrastructure.

Web Seminars

What's the best way to keep your network safe from malware? In this web seminar, security expert Greg Shields suggests an alternative method to the traditional blacklisting approach that is common with anti-virus and anti-malware solutions.

eLearning Series

We bring the experts direct to you to share their real-world perspective and expertise. During each event, three sessions stream in real time, so you can learn, ask questions, and get solutions.
Upcoming event: Getting the Most with Exchange 2010 with Paul Robichaux

Subscribe to Windows IT Pro!

Windows is a trademark of the Microsoft group of companies. Windows IT Pro is used by Penton Media Inc. under license from owner.