Disable a local account or issue one for a limited time
From a station page, disable a local account or issue a temporary local user. Windows is the full local-account model. Linux uses the same portal actions with a few differences.
Disable a local account or issue one for a limited time
When Vault/PAM is entitled and the station is on TAO 4.0.3554 or later, an operator can do more than rotate a password. Open the station and disable a local account, or issue a new local account that closes itself when the time ends.
The devices list does not run these actions. It shows how many stations have reported roles, how many enabled local administrators the fleet has, and how many enabled standard accounts. Stations still on an older agent report names only, until 4.0.3554 checks in. Open the hostname to work on that station.
Windows
On Windows, TAO reads the local account database, including accounts that are already disabled. An administrator is a member of the local Administrators group.
From the station page you can:
- See each local account, whether it is an administrator, and whether it is enabled.
- Disable an enabled account. TAO refuses the person who is signed in, the account selected for password rotation, and the last enabled local administrator.
- Issue a new account. Choose a standard user or an administrator, and a duration from 5 minutes to 24 hours. The usual choice is 30 minutes.
- Choose what happens when the time ends. The default is to disable the account. Delete is available only for an account TAO created. If deletion fails, TAO disables the account and reports the error.
The password is created on the station and stored in that station's vault. It appears in the station history after the station reports that the account exists. The same password is what the devices list reveals for that username.
TAO keeps the deadline on the station, so the account still closes if the portal cannot be reached. A station older than 4.0.3554 lists names only. Disable and issue stay unavailable there.
Usernames are 1–20 characters: letters, numbers, dots, dashes, or underscores. TAO rejects names that already exist, and reserved names such as Administrator, Guest, DefaultAccount, WDAGUtilityAccount, root, nobody, and trustity.
Domain and Active Directory accounts are not included.
Linux
The same station page works on a Linux host running TAO 4.0.3554 or later. The agent needs to run as root so it can read account state and create or lock accounts.
A few meanings differ from Windows:
- An administrator is root, or a member of sudo, wheel, or admin. There is no local Administrators group.
- Disabling an account locks it. It does not remove the account.
- The report counts human accounts: root, and accounts whose user id is 1000 or higher. System accounts are left out.
- If the agent cannot read the shadow file, a locked account can look enabled.
- Deleting an account TAO created also removes that account's home directory.
- The 20-character username limit still applies, so a name that is valid for Windows is valid here too.
The refusals are the same: the signed-in user, the rotation account, and the last enabled local administrator stay in place.
Operator practice
- Issue an administrator only for the window the task needs. Leave the end action on disable unless you intend to remove an account TAO created.
- Reveal the password on the station, or from the devices list for that same username. Both read the password stored for that account.
- Do not paste the password into a ticket or a chat.
- Confirm the station is on TAO 4.0.3554 before you expect roles, disable, or a timed account.
