purpleendurer注:
英文原文見:http://techrepublic.com.com/5100-1009_11-5692378.html?tag=nl.e102
這裡只翻譯其中具體操作的部分
Secure the local administrator account in Windows
windows系統中本地管理員帳號的安全
by Michael Mullins CCNA, MCP
Takeaway:
Did you know the Windows local administrator account is the only access someone needs to completely wreak havoc on your network? Locking down this account can go a long way toward securing your corporate systems. Mike Mullins offers some quick ways to better protect the local administrator account.
你是否知道,對於一個想發泄地破壞你的網路的人來說,擷取windows系統中本地dministrator帳號是他惟一的機會。
鎖定這個帳號可以使你的公司系統安全前進一大步。
邁克.馬林斯提供了一些快捷的方法來更好的保護本地administrator 帳號。
Secure the administrator account in Windows 2000
Windows 2000中的administrator帳號安全
Windows 2000 doesn't allow you to disable the administrator account. However, you can take steps to provide almost the same level of security as turning off this account. Follow these steps:
Windows 2000不允許禁用administrator帳號。然而,你可以採用一些步驟達到與關閉這個帳號同樣的效果。具體步驟:
Log on either as administrator or as a user with administrator permissions.
以其他管理員帳號或者具有管理員權限的使用者帳號登入。
Go to Start | Programs | Administrative Tools | Local Security Policy.
開始--》程式--》管理工具--》本地安全性原則
In the Local Security Settings console, expand Local Policies, and select User Rights Assignment.
在本地安全性原則設定控制台, 展開本地策略,選擇使用者權限指派
Double-click Deny Access To This Computer From The Network.
雙擊拒絕從網路訪問這台電腦
In the Security Policy Setting dialog box, click Add.
在安全性原則設定對話方塊中, 點擊添加。
In the Select Users Or Groups dialog box, select the administrator account, and click Add.
在選擇使用者或使用者組對話方塊中, 選擇administrator帳號,點擊添加.
Click OK twice, and close the Local Security Settings console.
點擊兩次確認,關閉本地安全性原則設定控制台。
Reboot the machine for the change to take effect.
重新啟動電腦以使改變生效
Disable the administrator account in Windows XP and Windows Server 2003
禁用Windows XP和2003中的administrator帳號
To disable the local administrator account, follow these steps:
按照以下步驟禁用本地administrator帳號
Log on either as administrator or as a user with administrator permissions.
以其他管理員帳號或者具有管理員權限的使用者帳號登入。
Right-click My Computer, and select Manage.
右擊我的電腦表徵圖, 從彈出的菜單中選擇管理
Expand Local Users And Groups, and select Users.
展開本機使用者和使用者組, 選擇使用者。
Double-click Administrator.
雙擊Administrator
Select the Account Is Disabled check box, and click OK.
選定禁用此帳號選擇框, 點擊確認。
Close the Computer Management console. The change will take effect after you log off the computer.
Final thoughts
關閉電腦管理主控台。
改變將在登出後生效。