Community discussions

MikroTik App
 
Hoov
Member Candidate
Member Candidate
Topic Author
Posts: 114
Joined: Fri Mar 30, 2018 9:08 am
Location: NE Michigan

default admin account

Tue Jul 11, 2023 10:43 pm

I have several hundred Mikrotik devices of various models I am managing, and I finally was able to take the time to setup usermanager. I was going to go thru at setup them all to use the usermanager, but I ran into one problem. How can I get rid of all the default admin accounts on these devices? As it sits right now I have to still have a Full account on each device so I can delete or disable Admin. Is that right?
 
msatter
Forum Guru
Forum Guru
Posts: 2915
Joined: Tue Feb 18, 2014 12:56 am
Location: Netherlands / Nīderlande

Re: default admin account

Tue Jul 11, 2023 10:50 pm

You can disable it, after taking away any rights to make changes.

Newer router come with a default password printed on the device so you need to register that also for each router.
 
Hoov
Member Candidate
Member Candidate
Topic Author
Posts: 114
Joined: Fri Mar 30, 2018 9:08 am
Location: NE Michigan

Re: default admin account

Tue Jul 11, 2023 11:04 pm

That is for the new Version 7 AX Routers, the non AX routers do not have the password on the box. We are using almost all older non AX routers. I have tried disabling the Admin account and could not. I actually just tried both a ROS version 6 and 7 non AX device, and it will not let me disable the Admin account or whatever account has the admin privilages. I must be doing something wrong.
 
msatter
Forum Guru
Forum Guru
Posts: 2915
Joined: Tue Feb 18, 2014 12:56 am
Location: Netherlands / Nīderlande

Re: default admin account

Tue Jul 11, 2023 11:39 pm

No you not doing anything wrong. It is protecting you from locking yourself out of the router.

You first have to create or have a second user with full access, and as you have already done.

Then set the Admin to read, apply, expire the password and then disable it. I prefer to expire the password after setting it to read. This to use it as a decoy/slowdown for any attackers.

update: you can even create a group with no rights instead of read. Hoping Mikrotik did not make the obvious mistake that no rights is the same as all rights. ;-)

Who is online

Users browsing this forum: No registered users and 4 guests