Identity Crisis

I once had a client that disabled the Administrator account in Active Directory and create an account with the name Elmer Fudd. Some people will argue that renaming privileged accounts to something other than “administrator” is a wasteful tumblr_mtqiit0xBz1qar86bo1_500 (1)“security by obscurity” defense. However, this simple security strategy works. If the attacker hasn’t already made it inside your network, there’s little reason to believe they’ll be able to readily discern the new names for your privileged accounts. If they don’t know the names, they can’t mount a successful password-guessing campaign against them.

Leave a comment