Microsoft’s official Group Policy blog
Have you ever wanted to configure a preference item to include a specific user name and password? You can do so in several types of preference items, but you should first consider the security ramifications of embedding a user name and password in a preference item.
Are passwords in preference items secure?A password in a preference item is stored in SYSVOL in the GPO containing that preference item. To obscure the password from casual users, it is not stored as clear text in the XML source code of the preference item. However, the password is not secured. Because the password is stored in SYSVOL, all authenticated users have read access to it. Additionally, it can be read by the client in transit if the user has the necessary permissions.
Because passwords in preference items are not secured, we recommend that you carefully consider the security ramifications when deciding whether to store passwords in preference items. If you choose to use this feature, we recommend that you consider creating dedicated accounts for use with it and that you do not store administrative passwords in preference items.
Where can you use passwords?You can use passwords in the following types of preference items:
For the user name in a Data Source, Mapped Drive, Scheduled Task, Immediate Task, or Service preference item, you can specify a local user account on multiple computers using the format .\UserName, or a domain account using the DomainName\UserName format.
So, yes, you can configure some types of preference items to include a user name and password, but because the password is merely obscured rather than secured, you should carefully evaluate the security ramifications for your situation to determine whether it is appropriate to use this feature.
Linda MooreTechnical Writer, Group Policy
(Reposted and updated on 22 April 2009)
PingBack from http://www.frickelsoft.net/blog/?p=184
少し前になるのですが、本社のグループポリシーチームのBLOGに以下の投稿がありました。 Passwords in Group Policy Preferences (updated) http://blogs.technet.com/grouppolicy/archive/2009/04/22/passwords-in-group-policy-preferences-updated.aspx
What a pain! So...how difficult would it be to "unobscure" a password stored in the xml file?
The capability of managing local administrator passwords has been a long sought feature...now I'm not comfortable recommending this as a solution.
I have written a blog article show how you can still use Group Policy to set password on local administrator accounts while only having a very small window of opportunity for someone to capture the obfuscated password from SYSVOL. This is in my opinion far more secure then haveing the same default local admin password on all your computers for years.