Panel | ||||||
---|---|---|---|---|---|---|
| ||||||
...
Sign in to Windows with an administrator account.
Go to Start button, type encryption in the search field, and select Manage BitLocker from the list of results.
Select Turn on BitLocker, and then follow the instructions.
- Be sure to escrow your BitLocker Recovery key in a safe location. UT provide the escrow service - STACHE as a free service to store sensitive information such as passwords, license information, or encrytion keys. For information on how to use STACHE, visit the documentation here
Anchor | ||||
---|---|---|---|---|
|
...
Running as an administrator? Administrative accounts are granted the ability to virtually perform anything on the computer. Every computer has an administrative account, and many users have the tendency to operating their computer in an administrative mode.
With an administrative account, malware/viruses have an easier time:
- Hiding itself in the system to install rootkits, backdoors, keyloggers.
- Creating new administrative accounts
- Accessing and running privileges services
- Using an infected system to attack other vulnerable computers on the network
If your current account is now an administrative account, you should downgrade this account with only “user” privileges, while also creating a new account for administrative purposes.
Important: Please Read - Information Security Office: How to Not Login as Administrator (and still get your job done)
Create a new Administrative Account
- Click on Start, then navigate to the Control Panel
- Select User Accounts and Family Safety, then User Accounts
- If you are currently in Small/Large icon view, proceed to click on User Accounts.
Note: Windows 8 and above, you can simply do a search for control panel and proceed with the remaining steps.
- Select Manage another account
- Select Create a new account
- Enter an account name, select Administrator, click Create Account
Assign a password to the new administrative account
- Click on the new account, select Create a password
- Enter a strong password and click Create Password when done
Demote the original user account to a standard user
- Select Manage another account
- Click on your original account from the accounts list (not the one recently created)
- Select Change the account type
- Select Standard User and click Change Account Type
- Close the Control Panel and then log off and back on the system with your primary/standard user account.
Anchor | ||||
---|---|---|---|---|
|
Password Complexity
...