Disable Administrator Account
Purpose
This solution is designed to identify and disable the built-in Administrator account on supported Windows devices through NinjaOne automation. It uses an organization-level custom field to determine whether the Administrator account should be disabled and applies the appropriate automation based on whether the device is a Windows Server or Windows Workstation.
The solution helps maintain a consistent security configuration across managed Windows devices by automatically remediating devices where the Administrator account is enabled and the organization setting requires it to be disabled.
Associated Content
Custom Field
| Content | Type | Function |
|---|---|---|
| cPVAL Disable Administrator Account | Custom Field | Controls whether the built-in Administrator account should be disabled for the organization and is used during compound condition evaluation. |
Automation
| Content | Type | Function |
|---|---|---|
| Disable Administrator Account | Script | Disables the built-in Administrator account on Windows devices when the solution requirements are met. |
Compound Conditions
| Content | Type | Function |
|---|---|---|
| Disable Administrator Account - Servers | Compound Condition | Targets supported Windows Server devices where the organization setting requires the built-in Administrator account to be disabled. |
| Disable Administrator Account - Workstations | Compound Condition | Targets supported Windows Workstation devices where the organization setting requires the built-in Administrator account to be disabled. |
Implementation
Step 1: Create the following Custom Field
Create the following custom field in NinjaOne:
Configure the custom field at the organization level to indicate whether the Administrator account should be disabled.
Step 2: Import the Automation Script
Import the following automation script:
Verify that the automation script is available and configured to run with the required permissions on the target Windows devices.
Step 3: Configure the Compound Conditions
Configure the following compound conditions and associate them with the appropriate device policies:
The compound conditions evaluate the organization-level custom field and device type to determine whether the automation should be executed.
Step 4: Configure the Organization Setting
For each organization where the Administrator account should be disabled, enable the appropriate value in the cPVAL Disable Administrator Account custom field.
FAQ
Q: Which devices are supported by this solution?
A: This solution is designed for supported Windows Server and Windows Workstation devices managed through NinjaOne.
Q: How does the solution determine whether the Administrator account should be disabled?
A: The solution uses the cPVAL Disable Administrator Account custom field to determine whether the organization has enabled the requirement to disable the built-in Administrator account.
Q: What happens if the built-in Administrator account is already disabled?
A: The automation will not need to perform the disable action when the account is already disabled.
Q: Does this solution disable other administrator accounts?
A: No. The solution is intended to disable the built-in Windows Administrator account and does not target other user accounts unless specifically configured by the automation.
Q: Does the solution apply to both servers and workstations?
A: Yes. Separate compound conditions are provided for Windows Servers and Windows Workstations to ensure the appropriate devices are targeted.
Q: Can the solution be enabled for selected organizations only?
A: Yes. The organization-level cPVAL Disable Administrator Account custom field controls whether the solution should apply to an organization.
Q: Is manual configuration required on each device?
A: No. Once the custom field, automation, and applicable compound conditions are configured, the solution can automatically apply the required configuration to eligible devices.
Q: What happens if the organization setting is not enabled?
A: The compound conditions will not target the device for remediation, and the Administrator account will not be disabled by this solution.
Changelog
2026-10-01
- Initial version of the document.