How to identify and remove default XProtect Basic User account
A default XProtect Basic User account admin with default password admin may be created during the installation process. To prevent undesired access via XProtect Mobile, Web, or Smart Clients, the Basic User admin must be deleted or the password must be changed. Affected XProtect versions:
XProtect Go (all versions)
XProtect Express 2017 R1 (11.1a) and prior versions
XProtect Essential 2.0 - 2017 R1
To check for the issue:
Open the "XProtect Management Application" and go to "Users."
If you see user admin with the User Type Basic, right-click the user and select either "Delete User" or "Properties --> User Information" to change the password.
Article Number
000002472