Skip to main content

Disable Administrator Account

Purpose​

This solution is designed to identify and disable the built-in Administrator account on supported Windows devices through NinjaOne automation. It uses an organization-level custom field to determine whether the Administrator account should be disabled and applies the appropriate automation based on whether the device is a Windows Server or Windows Workstation.

The solution helps maintain a consistent security configuration across managed Windows devices by automatically remediating devices where the Administrator account is enabled and the organization setting requires it to be disabled.

Associated Content​

Custom Field

ContentTypeFunction
cPVAL Disable Administrator AccountCustom FieldControls whether the built-in Administrator account should be disabled for the organization and is used during compound condition evaluation.

Automation

ContentTypeFunction
Disable Administrator AccountScriptDisables the built-in Administrator account on Windows devices when the solution requirements are met.

Compound Conditions

ContentTypeFunction
Disable Administrator Account - ServersCompound ConditionTargets supported Windows Server devices where the organization setting requires the built-in Administrator account to be disabled.
Disable Administrator Account - WorkstationsCompound ConditionTargets supported Windows Workstation devices where the organization setting requires the built-in Administrator account to be disabled.

Implementation​

Step 1: Create the following Custom Field

Create the following custom field in NinjaOne:

Configure the custom field at the organization level to indicate whether the Administrator account should be disabled.

Step 2: Import the Automation Script

Import the following automation script:

Verify that the automation script is available and configured to run with the required permissions on the target Windows devices.

Step 3: Configure the Compound Conditions

Configure the following compound conditions and associate them with the appropriate device policies:

The compound conditions evaluate the organization-level custom field and device type to determine whether the automation should be executed.

Step 4: Configure the Organization Setting

For each organization where the Administrator account should be disabled, enable the appropriate value in the cPVAL Disable Administrator Account custom field.

FAQ​

Q: Which devices are supported by this solution?

A: This solution is designed for supported Windows Server and Windows Workstation devices managed through NinjaOne.

Q: How does the solution determine whether the Administrator account should be disabled?

A: The solution uses the cPVAL Disable Administrator Account custom field to determine whether the organization has enabled the requirement to disable the built-in Administrator account.

Q: What happens if the built-in Administrator account is already disabled?

A: The automation will not need to perform the disable action when the account is already disabled.

Q: Does this solution disable other administrator accounts?

A: No. The solution is intended to disable the built-in Windows Administrator account and does not target other user accounts unless specifically configured by the automation.

Q: Does the solution apply to both servers and workstations?

A: Yes. Separate compound conditions are provided for Windows Servers and Windows Workstations to ensure the appropriate devices are targeted.

Q: Can the solution be enabled for selected organizations only?

A: Yes. The organization-level cPVAL Disable Administrator Account custom field controls whether the solution should apply to an organization.

Q: Is manual configuration required on each device?

A: No. Once the custom field, automation, and applicable compound conditions are configured, the solution can automatically apply the required configuration to eligible devices.

Q: What happens if the organization setting is not enabled?

A: The compound conditions will not target the device for remediation, and the Administrator account will not be disabled by this solution.

Changelog​

2026-10-01​

  • Initial version of the document.