increase your machines security with a unique local-administrator password
Set up Active Directory so that users who were locked outside their Windows machine and are off-site can nevertheless get access to their local machine in a secure, effective manner In a nutshell: Extend the A/D Schema For computer objects, add a localAdminPwd field Set an ACL on this field: only accesible to Domain Admins and your helpdesk team Configure Group Policy local administrator: denied log on from the network Set random password for each local administrator Use a script to generate a random password store password in A/D set the password on the machine's administrator account if you fail, role back so the two are always in sync Add scripts to the Active Directory Users and Computers administrative tool "Get local admin password" - will show helpdesk members the current password for a given computer account "Set local admin password" - will generate a random password and set it on the machine and in A/D (or roll back) ...