When joining a Windows workstation to an Active Directory domain, what should you do with any local user accounts that are not strictly required for recovery or management purposes?
In a domain environment, centrally managed domain credentials should be used wherever possible. Disabling unneeded local user accounts reduces the attack surface, prevents lateral-movement attacks that leverage cached local credentials, and stops former employees whose domain accounts are disabled from signing on with leftover local accounts. Microsoft's security baselines note you can operate with no administrative local accounts enabled and rely solely on domain accounts for administration.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is Active Directory and how does it work?
Open an interactive chat with Bash
What are the security vulnerabilities of using local user accounts?
Open an interactive chat with Bash
What does it mean to authenticate users via a domain controller?