Built-in Administrator Account Disabled

Darren Canavor, Program Manager on the UAC team has made a post on the Windows Vista Security blog about changes to the behavior of the built-in Administrator account:

“In Windows Vista we made numerous changes to our user account model. Standard users are now the default user type for new accounts created after initial setup. The Power Users group is effectively deprecated. In addition, we’ve made it much easier to run as a standard user and even administrators run with limited Windows privileges and user rights by default. But people often ask us, “What about the built-in administrator account? Isn’t it a security risk to have an administrator account with no password?” Yes, in some cases this administrator account could be used to circumvent other security mechanisms. For example, parental controls could not be effective if the child could simply login with the built-in administrator account and do whatever they want, including disabling the Parental Controls.

In Windows Vista RC1 we will have completed a series of changes to disable the built in administrator account under most circumstances. These changes apply to the default administrator account named Administrator, which is created during setup.”

See full post at https://blogs.msdn.com/windowsvistasecurity.

Comments

  • Anonymous
    August 31, 2006
    Happy Day!! :-)

  • Anonymous
    September 11, 2006
    if the built-in administrator is disabled and if it doesn't work in safe mode, why the administrator account is created in Vista? it's totally useless having the administrator account, because you've just a protected administrator created during the first installation.

  • Anonymous
    September 25, 2006
    Ok you disable the built-in account and then you created the trusthandler account,,which let's the system run the show,,,,, Why create Admin Acc at all.... there are files that could become corrupt that only the trusthandler can delete,,,not the Admin...Explain please I'm I missing something..

  • Anonymous
    October 06, 2006
    If you re-enable the admin account, does it allow you to bypass the UAC screen-darkening if you do a runas?

  • Anonymous
    October 09, 2006
    The comment has been removed

  • Anonymous
    October 11, 2006
    The comment has been removed

  • Anonymous
    October 28, 2006
    I cursed UAC when I was testing Vista. But now that I'm trying to run as a limited user on XP, I'd welcome the feature. I didn't realize all of the obstacles I'd run into with application programs and the operating system utilities. The runas command is of limited use because when it is used you are in another user's enviroment with their settings. Herbert, for XP take a look at MakeMeAdmin.  Lots more info about running as a non-admin on XP here. HTH -- Aaron Margosis

  • Anonymous
    November 17, 2006
    I installed rc1 for testing, now i can't access my computer.The administrator is disabled in safe mode. i don't have any other user name. i am locked out. can somebody help me. I'm stuck on the start up screen.

  • Anonymous
    December 27, 2006
    One can build another user account via Safe Mode if you need to. You dont have to re-install the O/S altogether.

  • Anonymous
    January 22, 2007
    How? I'm in safemode and it's telling me to click a username. there are none!!

  • Anonymous
    February 22, 2007
    The comment has been removed