yes, you can (and SHOULD) make another administrator account, and disable the default.
[> normis@demo2.mt.lv> ] > user group print
0 name=“read” policy=local,telnet,ssh,reboot,read,test,winbox,password,web,sniff,
!ftp,!write,!policy
1 name=“write” policy=local,telnet,ssh,reboot,read,write,test,winbox,password,web,
sniff,!ftp,!policy
2 name=“full” policy=local,telnet,ssh,ftp,reboot,read,write,policy,test,winbox,
password,web,sniff
3 name=“demo” policy=local,telnet,ssh,read,winbox,!ftp,!reboot,!write,!policy,!test,
!password,!web,!sniff
[> normis@demo2.mt.lv> ] > > user add name=normis group=full password=test
to reset http://wiki.mikrotik.com/wiki/Password_reset