Exclusively for TechExams members for Infosec Boot Camps starting before April 30, 2026
Markie wrote: Although, I agree with what you say, don't you think that this type of behaviour takes away some of the credibility with respect to computer accounts?
Markie wrote: In small to medium sized businesses, where they may use a mixture of domains and workgroups (as workgroups are cheaper and easier to configure), there's bound to be the odd occassion when the name of local machine accounts match domain accounts. All you need is a matching password and you have a security problem.
Markie wrote: I mean, besides the "log on to" option disappearing from the logon screen (after a computer a/c has been disabled in Active Directory), I can't really see any other benefits from using computer accounts if this flaw exists.
Markie wrote: So much for the supposed "security channel" (thats the channel that the DC uses to communicate with valid computer accounts).
Markie wrote: I suppose the other workaround besides ensuring no identical passwords are in place, is to keep the workgroups and domains on different subnets. At least I won't make this mistake as a Systems Admin in the future.
Exclusively for TechExam members. Applies to boot camps starting before April 30, 2026.