Centrify - Securing the Cross Platform Data Center

The Centrify Apple Guys

LMcAndrew

Creating a local Mac administrator account that is invisible

by ‎03-23-2012 04:21 PM - edited ‎03-23-2012 04:21 PM

Best practices for integrating with AD suggest that you keep a local administrator account on your Mac. It's possible to create this local administrator account and keep it hidden from users.

 

When you unbundle a new Mac, you'll need to create an admin account anyway. You use this to install Centrify and bind to Active Directory.

 

When you create a local admin account, give it the name ".admin" (with a period in front).

 

It won't show up in the list of users under System Preferences -> Users and Groups

 

Screen Shot 2012-03-23 at 4.02.03 PM.png

 

 

 

When the regular AD user logs in, it won't show up in the Users and Groups display.

 

 

 

 

Screen Shot 2012-03-23 at 4.11.34 PM.png

 

However, when you log in with the hidden admin account, it will show up in Users and Groups. 

 

Screen Shot 2012-03-23 at 4.15.58 PM.png

 

Thanks to Steven H for the tip.

 

 

Comments
by Centrify on ‎03-23-2012 04:54 PM

Pretty cool, but now I have to know where you've installed these hidden admin accounts. How can I see if the machine has a hidden admin account or not, is there a CLI command to show the account?

by Shaun Prince(anon) on ‎09-21-2012 09:05 AM

from a terminal, you should be able to use:

ls -al /Users

 

by Juno(anon) on ‎04-20-2013 02:39 AM

and how to unhidden??

Post a Comment
Be sure to enter a unique name. You can't reuse a name that's already in use.
Be sure to enter a unique email address. You can't reuse an email address that's already in use.
Type the characters you see in the picture above.Type the words you hear.
About the Author