1. Security tasks

Change the administrator password

Version:
Applies toAll core roles
Sitecore Installation FrameworkAdministrator password parameter available (SitecoreAdminPassword). In 9.0.2 and earlier, SIF does not enforce changing the administrator password. In 9.1 and later, SIF will generate a random password if you do not change the default value.
Azure ToolkitAdministrator password is changed by default - enforced by ARM template.

Before you deploy your Sitecore installation, you must change the administrator password to a strong password. Changing the password prevents unauthorized users from using the default password to access the admin account.

Create a new administrator account

As an extra layer of protection, Sitecore recommends that you create a new administrator account, with a unique name, and disable the out-of-the-box administrator account.

If you have suggestions for improving this article, let us know!