📎 AI Summary:
The thread discusses best practices for managing the default administrator account on Windows 7 PCs within a domain. The original poster asks whether it's advisable to leave the default admin account disabled and create a separate local admin account, and whether the default account can be reactivated if needed. Respondents recommend disabling the default admin account for security reasons and creating a strong, separate local administrator account, confirming that the default account can be re-enabled if necessary. Overall, the advice favors disabling the default account to enhance security while retaining the ability to activate it if required.

ScienceJohn

Well-Known Member
Joined
Feb 28, 2012
Messages
4
Thread Author #1
Hi all,

I have a load of Windows 7 laptops/pc's on a domain and wondered if the general feeling was to leave the default administrator acct disabled and create another local admin (although obviously I realise there will be domain admins as well)

It was my understanding that leaving it disabled and not changing the password allows you to activate it should you need to ??

Open to advice

Thanks
 

Solution
I would recommend that you keep the default admin account disabled, and that you create a local admin account. (In the event that the domain goes down)

If you are in a live production environment I recommend creating very strong passwords consisting of several uppercase, lowercase, symbols and numbers to ensure the safety of the machines against threats.

If creating a test environment, since security isn't an issue a simply password should be sufficient.

To answer your second question...

"It was my understanding that leaving it disabled and not changing the password allows you to activate it should you need to ??"

Yes leave it disabled.

TechGoudy

New Member
Joined
Sep 16, 2011
Messages
32
I would recommend that you keep the default admin account disabled, and that you create a local admin account. (In the event that the domain goes down)

If you are in a live production environment I recommend creating very strong passwords consisting of several uppercase, lowercase, symbols and numbers to ensure the safety of the machines against threats.

If creating a test environment, since security isn't an issue a simply password should be sufficient.

To answer your second question...

"It was my understanding that leaving it disabled and not changing the password allows you to activate it should you need to ??"

Yes leave it disabled.
 

Solution