Skip to content
Dynamics 365 Blog

When you deploy a cloud-hosted Dynamics AX 2012 demo environment from Lifecycle Services (LCS), the password for Administrator is fixed and well known.

We have discovered that this causes unauthorized usage via RDP and hackers can use it to spread viruses and malware.

 

After the AX 2012 demo environment has been deployed to Azure, then you should change the password for the Administrator account.

In case you should forget the administrator password, it can be reset https://azure.microsoft.com/en-in/documentation/articles/virtual-machines-windows-reset-rdp/

Note that there are a few other user accounts that also have administrator permissions which could be used for remote access. Since some of these user accounts are used as service account there will be quite a job to change password on these accounts. Therefor an option is to restrict the allowed IP addresses in the firewall. Here are some articles about that:

https://technet.microsoft.com/en-us/library/cc753558.aspx

http://www.cm3solutions.com/block-ip-address-ip-range-using-windows-firewall/

http://superuser.com/questions/268902/how-to-block-all-traffic-but-one-ip-in-windows-firewall

We're always looking for feedback and would like to hear from you. Please head to the Dynamics 365 Community to start a discussion, ask questions, and tell us what you think!