+ Reply to Thread
Results 1 to 15 of 15

Thread: How does your school handle Tech accounts.

  Share/Bookmark
  1. #1

    Reputation
    Disease's Avatar
    Join Date
    Jan 2006
    Posts
    608
    Thank Post
    25
    Thanked 9 Times in 9 Posts
    Rep Power
    0

    Default How does your school handle Tech accounts.

    I am looking to overhaul things here, currentlt techs log in using the Domain admin account when ever tey want to do anything (I know, I know we should not be doing it), I want to change things to proper best practice and was wondering how you set your tech accounts up, what privileges do you give them, do you use a specific GPO etc.

    Thanks.

  2. #2

    Reputation Reputation
    tommej's Avatar
    Join Date
    Oct 2009
    Location
    Lincolnshire
    Posts
    193
    Thank Post
    10
    Thanked 15 Times in 13 Posts
    Rep Power
    7

    Default

    We used to have a single account all our techs used but with people leaving etc the password had to be changed often and it was hard to keep track of who knew what. It was also impossible to audit, so now all the techs have their own account with no restrictions.

  3. #3

    Reputation Reputation Reputation Reputation Reputation Reputation Reputation Reputation Reputation Reputation Reputation Reputation
    Edu-IT's Avatar
    Join Date
    Nov 2007
    Posts
    4,023
    Thank Post
    196
    Thanked 287 Times in 267 Posts
    Rep Power
    76

    Default

    We have one domain administrator account, a system administrator account and then our own individual logins which are just regular staff accounts. On a daily basis we can do everything we need from the staff accounts.

  4. #4
    rad
    rad is offline

    Reputation Reputation Reputation Reputation
    rad's Avatar
    Join Date
    Jan 2009
    Location
    Middlesex
    Posts
    708
    Thank Post
    49
    Thanked 57 Times in 37 Posts
    Rep Power
    17

    Default

    We have an admin account and our own individual accounts which also have admin rights.

  5. #5

    Reputation

    Join Date
    Nov 2009
    Location
    leeds
    Posts
    10
    Thank Post
    0
    Thanked 0 Times in 0 Posts
    Rep Power
    0

    Default

    what o/s are you using, if you are using windows 2003 r2 create a tech group decide what right's they have.You can then add or take away members when you want too.

  6. #6

    Reputation
    Reputation Reputation Reputation Reputation Reputation Reputation
    elsiegee40's Avatar
    Join Date
    Jan 2007
    Location
    Kent
    Posts
    4,110
    Thank Post
    573
    Thanked 511 Times in 381 Posts
    Rep Power
    135

    Default

    I'm on my own, but I have my own Domain Admin account - logging on as Administrator is a last resort.

    However, my Domain Admin account is not my day-to-day account... too dangerous, I don't trust myself!

    My main account has conventional staff privileges. I do most things from that (including Remote Desktop into the server), only using the Domain Admin account if I have to.

  7. #7


    Reputation Reputation Reputation Reputation Reputation Reputation Reputation Reputation Reputation Reputation Reputation Reputation
    tom_newton's Avatar
    Join Date
    Sep 2006
    Location
    Leeds
    Posts
    2,489
    Thank Post
    272
    Thanked 342 Times in 259 Posts
    Rep Power
    78

    Default

    We have our own accounts, plus an admin account each. Eg. "bob.smith" and "bobadmin"

  8. Thanks to tom_newton from:

    plexer (09-11-2009)

  9. #8

    Reputation

    Join Date
    Oct 2009
    Location
    Connecticut
    Posts
    22
    Thank Post
    0
    Thanked 2 Times in 2 Posts
    Rep Power
    2

    Default

    Everyone has their own accounts. Of course domain administrator account separate, though most of us have enough rights not to need it. All students/stuff, etc have their own accounts as well. It's pretty simple, we have automated batch scripts that add account for us. We use GPOs made with different restrictions for staff/students.

  10. #9

    Reputation Reputation
    fawkers's Avatar
    Join Date
    Jun 2007
    Location
    Southend
    Posts
    101
    Thank Post
    17
    Thanked 14 Times in 13 Posts
    Rep Power
    11

    Default

    Hi fokes

    We have a normal staff user account, a <initials>.admin account which has delegated permissions for the jobs that we do (local admin on workstations, servers and delegated permissions to ad, gpmc etc). Only the network manager has an admin account with domain admin privileges.

  11. #10

    Reputation Reputation

    Join Date
    Apr 2008
    Location
    Cumbria
    Posts
    236
    Blog Entries
    2
    Thank Post
    87
    Thanked 37 Times in 37 Posts
    Rep Power
    11

    Default

    Here currently I have my own standard user account, a standard domain account which is added to the local admins group on each workstation and then domain admin accounts are only used on the servers.

    Part of the system I inherited and seems to work quite well actually.

  12. #11

    Reputation Reputation Reputation Reputation
    ajbritton's Avatar
    Join Date
    Jul 2005
    Location
    Wandsworth
    Posts
    1,630
    Thank Post
    17
    Thanked 73 Times in 43 Posts
    Rep Power
    26

    Default

    IMHO, best practise is as per Tom_Newton's post.

    Each users gets a 'standard' account which can be used to log on to the domain and do basic working tasks (Office, Email, Internet etc).

    Any users who perform 'admin' tasks should have an additional user account, also unique to them which is used just these purposes.

    This follows the principles of least privilege. Users needing to do 'admin' tasks either log on to a PC with their admin account or (as I do) use RunAs to run an Admin tool with elevated privileges.

    The Admin account should also only have the essential permissions. For example, my own 'admin' account has not access to Internet or Email as this would duplicate what I can already do with my normal account.

    This way of working is initially burdensome to those used to logging on as a Domain Admin all the time but it's surprising how quickly you get used to it.

  13. #12

    Reputation Reputation Reputation Reputation Reputation Reputation Reputation Reputation Reputation Reputation Reputation Reputation Reputation Reputation Reputation
    FN-GM's Avatar
    Join Date
    Jun 2007
    Location
    Rochdale, Lancashire
    Posts
    8,813
    Thank Post
    309
    Thanked 611 Times in 554 Posts
    Rep Power
    120

    Default

    IT staff have there own account with Domain Admin rights.

    The Administrator account everyone uses for server stuff

  14. #13

    Reputation
    Disease's Avatar
    Join Date
    Jan 2006
    Posts
    608
    Thank Post
    25
    Thanked 9 Times in 9 Posts
    Rep Power
    0

    Default

    Thanks for all te replies, it's given me something t work with now. Thanks.

  15. #14

    Reputation Reputation Reputation Reputation Reputation Reputation Reputation Reputation Reputation Reputation
    cookie_monster's Avatar
    Join Date
    May 2007
    Location
    Derbyshire
    Posts
    4,040
    Thank Post
    299
    Thanked 263 Times in 226 Posts
    Rep Power
    63

    Default

    We have a domain admin account that everyone (members of the IT team of course) uses BUT it's only allowed to logon to servers. Each user has an ordinary user account for general use then we have a domain user that we make a member of local administrators on all stations using GPO restricted groups. This account has no access to the servers or shared areas it can only see our software share and a tools folder for troubleshooting.

  16. #15

    Reputation Reputation Reputation Reputation Reputation Reputation Reputation Reputation Reputation Reputation Reputation Reputation
    RabbieBurns's Avatar
    Join Date
    Apr 2008
    Location
    Sydney
    Posts
    3,223
    Blog Entries
    5
    Thank Post
    516
    Thanked 267 Times in 155 Posts
    Rep Power
    71

    Default

    All our servers run TS so we each have our own accounts which are domain admin accounts and we each individually log onto servers so all stuff can be accounted / attributed to an individual user.

+ Reply to Thread

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

     

Similar Threads

  1. How does your school handle purchases?
    By RallyTech in forum How do you do....it?
    Replies: 11
    Last Post: 06-11-2009, 08:08 PM
  2. ideal tech department for k-12 school
    By LCPSWolf in forum How do you do....it?
    Replies: 0
    Last Post: 05-09-2009, 02:40 AM
  3. Other school tech forums????? rescources
    By dunkydonut in forum General Chat
    Replies: 7
    Last Post: 16-09-2008, 12:34 PM
  4. Why are you a school tech?
    By ITWombat in forum General Chat
    Replies: 34
    Last Post: 12-03-2007, 12:06 PM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts