A hardening review proposes disabling every locally defined account the day directory login is confirmed working, leaving directory credentials as the only way in. The engineer is asked to sign off. What makes that recommendation dangerous?
Select an answer to reveal the explanation.
Short Explanation
Here's the trap: the directory looks invincible right up until the night it's down - and the appliance you urgently need is locked behind it. Keep one local administrator account alive as your break-glass path, sealed and monitored, just never convenient. Hardening that locks you out isn't hardening.
Full Explanation
Directory authentication moves the front door onto infrastructure that lives elsewhere: domain controllers, the network path to them, DNS, time sync. Any of those can be unavailable at precisely the moment the appliance most needs human hands - a broad outage that has already taken the directory down - and an absolute 'no local accounts' policy turns a bad night into a locked-out server room. Keeping at least one local administrator account enabled, tightly held and escrowed, is therefore standard resilience design, not a hardening oversight. The 'directory is more available' argument ignores that availability is a property of the whole path, not of the service alone, and the worst access lockouts in practice happen during correlated outages. The audit-trail claim fails by concept: appliance logging attributes events to whichever identity successfully authenticates, local or directory, and disabling unused local accounts removes nothing that logging depends on. The monitoring claim is also wrong: SNMP polling authenticates through its own SNMP user or community configuration and alert delivery uses its SMTP settings - neither logs in as a local administrative user. Exam caveat: the surviving local account belongs to the escrow and rotation practice, with its use treated as an exception, not a routine. Operational check: with directory authentication deliberately blocked at the firewall, the break-glass account still logs in, and its use is ticketed and reviewed afterward.