Windows IT Pro is the leading independent community for IT professionals deploying Microsoft Windows server and client applications and technologies.
  
  
  Advanced Search 


November 06, 2009

Security Steps:Use Syskey on Windows 7 to encrypt the SAM to stop someone resetting the local admin password on a netbook

RSS
Subscribe to Windows IT Pro | See More Systems Administration Articles Here | Reprints | Or get the Monthly Online Pass—only $5.95 a month!
back to blog index

Very few netbook computers support BitLocker, which means that they are vulnerable to utilities that allow you to boot from a USB device and reset the local administrator password. The way to ensure that this type of attack doesn’t work is to use SYSKEY to encrypt the SAM database.

SYSKEY is a tool that has been around for some time on Windows client operating systems, but most administrators don’t bother using it because it makes recovering a computer difficult in the event that a user forgets their password. In some cases you want to do all that you can do to protect the data on a netbook computer. To do this, you should use SYSKEY to encrypt the SAM database and use EFS to encrypt any locally stored files and folders. To accomplish this, perform the following steps:

  1. Log on to Windows 7 with an account that has local administrator access
  2. Type SYSKEY into the textbox on the start menu. Click OK at the UAC prompt.
  3. Select the Encryption Enabled Option.
  4. Select the Password Startup Option. Enter the Startup Password that must be entered each time.
  5. Reboot the computer.

From now on the Startup Password must be entered to unlock the SAM database before local logon will be allowed.

You can see these steps in the following video:

End of Article



Reader Comments

You must be a registered user or online subscriber to comment on this article. Please log on before posting a comment. Are you a new visitor? Register now





Search Hyperbole, Embellishment, and Sys Admins
 
Hyperbole, Embellishment, and Sys Admins
NOVEMBER 2009
1 2 3 4 5 6 7
8 9 10 11 12 13 14
15 16 17 18 19 20 21
22 23 24 25 26 27 28
29 30      
or

 Recently in Hyperbole, Embellishment, and Sys Admins
Security Steps: Restricted Groups Policies
Make a Comment
Security Steps:Use Syskey on Windows 7 to encrypt the SAM to stop someone resetting the local admin password on a netbook
Make a Comment
WSUS, Server 2008 R2 and BranchCache
Make a Comment
Security Steps: How to block the installation of the Chrome Frame add-on for Internet Explorer
Make a Comment
Security Steps: Firing a Systems Administrator

Last Comment
Even when the user's account is disabled, those same admins also often know the credentials of privi...
(2 Comments)

More blogs about technology,
software, and Windows.

Windows IT Pro Home Register FAQ for Windows WinInfo News
Europe Edition About Us Contact Us/Customer Service Media Kit Affiliates / Licensing  
SQL Server Magazine Office & SharePoint Pro DevProConnections IT Job Hound
Left-Brain.com Technology Resource Directory asp.netPRO ITTV Windows SuperSite 
 
 Windows IT Pro is a Division of Penton Media Inc.
 © 2009 Penton Media, Inc. Terms of Use | Privacy Statement