- 2
- 0
- 1
When our SCCM install was first configured, it was set to use the default administrator AD account. I'm wanting to divorce ourselves from this obvious security issue. I've gone through and changed the network access account and client push accounts, but I'm still seeing the administrator user pop up in my Defender for Endpoint activity logs on our Windows endpoints. I'm hoping you guys can point me in the direction of what I've missed - thanks!
Both of these entries are being reported by our Windows endpoints on a regular basis.
Code:
Resource access: device SCCMSERVER, property Spns cifs/SCCMSERVER.domain.local Resource access: property Spns krbtgt/DOMAIN.LOCAL, user krbtgt
Both of these entries are being reported by our Windows endpoints on a regular basis.