The administrator password is the only thing between your server and the bots that scan port 3389 non-stop. Change it as soon as it has travelled by e-mail or chat, and whenever someone who knew it leaves your project.
How do I change the administrator password from Windows?
Open a Remote Desktop session, press Ctrl + Alt + End, then choose Change a password.
This is the most direct route and it takes effect immediately.
- Connect over Remote Desktop.
- Press
Ctrl + Alt + End(notCtrl + Alt + Del, which your own computer would capture). - Choose Change a password.
- Enter the old password, then the new one twice.
- Confirm. The session stays open; the new password applies at the next login.
On the command line, in a prompt run as administrator:
net user Administrator *
Windows then asks for the new password without displaying it. Replace Administrator with the real account name if you chose a different one when ordering.
How do I change my VPS password from the client area?
In My services > your VPS > Accès & Sécurité, the Change Password card — then reboot the VPS, otherwise the old password stays active.
The client area can also push a new password to the machine.
- Open My services, then your VPS.
- Go to the Access & Security tab.
- In the Change Password card, type the new password. The Generate a password button suggests one that matches the policy below.
- Click Change Password and confirm.
- Then reboot the VPS from its service page. On Windows VPS the password is handed to the machine by the system initialisation mechanism, which runs at boot: without a reboot the old password may keep working.
The change is recorded in the History tab as "Mot de passe modifié."
If the new password is still refused after a reboot, open the rescue console and apply method 1 from the machine's own screen. That path always works.
Which rules must my VPS password follow?
Between 12 and 64 characters, with at least one lower-case letter, one capital, one digit and one symbol, and no obvious word or run of characters.
The client area rejects weak passwords at order time, at reinstallation and when changing them. An accepted password must:
- be between 12 and 64 characters;
- contain at least one lowercase letter, one uppercase letter, one digit and one symbol;
- use only letters, digits and the symbols
!@#%^&*()-_=+[]{}:;,.?— no space, quote, backslash or accented character, because those are lost on the way to the machine; - contain no obvious word (
admin,root,windows,qwerty,password,123456…); - not reuse the hostname of your VPS, your user name or the hosting company name;
- not contain three identical characters in a row (
aaa) or a run of four consecutive characters (abcd,4321).
A reworked passphrase remains the best balance between strength and memory, for example Three-Cats!Sleep92.
What should I do after changing the password?
Reconnect once to check it, update your password manager, and make sure no unknown account has appeared on the machine.
- Reconnect once to confirm the new password works before closing all your sessions.
- Update your password manager. Do not keep the old password "just in case".
- Check under Computer Management > Local Users and Groups that no unknown account has appeared.
- If you suspect the old password was compromised, changing it is not enough: assume the machine is compromised too and plan a reinstallation after backing up your data.
By-Hoster support will never ask for your password in a ticket. Do not paste it into a conversation, not even to save time.