Jump to content

Recommended Posts

Posted

Bit random...

 

I was approached by SLT and asked to give admin level rights (as in admin password to one designated memeber of staff) so in case when I am not onsite or if I die all of a sudden then they have a way of gaining access to the network?

 

Whats your view on this?

 

Would you?

 

If Yes? why?

 

If No? Why?

Posted

There needs to be a documented procedure in place for this and if you are the only IT support person on site it should be something along the lines of username/password secured in school safe.

 

Ben

  • Thanks 1
Posted

We have all admin related passwords on an encrypted memory stick in the safe.

 

Ask him if the system went down and all the data went and he wanted someone to blame his name would be in the hat also, as he has admin access!

  • Thanks 1
Posted
Why not just have the password in a sealed envelope in a safe?

 

If you laminate the envelope leaving plenty of empty plastic along all edges you will be able to see it hasn't been tampered with.

Posted
Create a unique separate account with administrator privileges... that way any activity on it can be tracked and seperated from your actual administrator account. As per everyone else - sealed destructive envelope in safe or encrypted memory stick in safe, and presuming all staff don't have access to the safe, a specific signing out sheet left with whoever is in charge of the safe which must be completed whenever the details are removed / used.
  • Thanks 1
Posted
Create a unique separate account with administrator privileges... that way any activity on it can be tracked and seperated from your actual administrator account. As per everyone else - sealed destructive envelope in safe or encrypted memory stick in safe, and presuming all staff don't have access to the safe, a specific signing out sheet left with whoever is in charge of the safe which must be completed whenever the details are removed / used.

 

This.

 

Nobody gets my password!

  • Thanks 1
Posted
lol

 

would love to know your rationale...

 

As a lot of SLT are not IT Professionals and think that just because BitCommet works well at home that it won't harm to have it on the school computer or the 100 stupid add-on toolbars in IE etc... Seeing how some SLT I have worked with (not all) use a computer and click blindly and randomly, I'd expect a network to last all of 5 minutes with them!

  • Thanks 1
Posted (edited)
lol

 

would love to know your rationale...

 

For the same reason I tell staff not to give anyone, even me, their password. It is my account so anything that happens on it is my responsibility. If I give out my password to anyone, even SLT, then that increases risk of something happening but doesn't decrease my responsibility.

 

Odd response from an IT bod really.

Edited by TechMonkey
  • Thanks 1
Posted
When I first started here about 3 of the SLT had administrative access or local admin passwords purely because they were in senior positions, one of them would buy and install printers for staff and install random toolbars(sparklebox!) or software upon request despite me asking him not to... now I'm the only one with admin access - as with most others a password list is in the safe along with full documentation.
  • Thanks 1
Posted
We have a separate account (the domain's default Administrator account) with its password stored in the safe, but TBH I don't really class this as "giving SLT admin access". To my mind that would be more like what @Jamman960 is referring to.
Posted

Yes/No - depends which member of SLT wanted it! Some would worry me more than others.

 

We are much the same as others in that our contingency is a copy in the safe where we keep a copy of the credentials for the lastpass account which holds all (probably not quite yet) the other passwords. Our backup to that is a book.

Posted

Explain the issue very carefully, including the worst-case-scenario and the "password in a safe" solution.

Then, if they insist -explain some more, detail your objections and document your explanation in an email or something so it is written down for future reference

If they still insist - create the separate admin acct as detailed above -perhaps restricting them to super-user?

Posted
That's another point; for what many of them would ask for, full Enterprise Admin access may not be needed and you may well be able to "get away" with an account that has local admin access to all workstations plus e.g. full control permissions cascaded downwards from the root of your file servers' data volumes.
Posted
Why would they need it?

 

Passwords are like underwear - change them regularly and never share them.

 

You see, I've never shared my password, cos I could be blamed for anything done under those account details, but now you've put it like that, it sounds fun :p

  • Thanks 1
Posted (edited)
This.

 

Nobody gets my password!

lol

 

would love to know your rationale...

There is history...

 

... involving a headteacher, a holiday, a password, a safe and a third party supplier...

 

... it was the last straw.

 

Don't believe it would never happen @Get2theChoppa. I had been in the industry for over 20 years when it did :( Protect yourself and your network.

Edited by elsiegee40
  • Thanks 2
Posted
Just ask them to explain why they think they need this level of access.

 

Ben

Well, you can ask, but as they are SLT they outrank you and can do what they like. It is neither "your" network nor "your" password so the only thing you can do is tell them why it is not a good idea and ask them what they are thinking that they might need to do when you are not there

  • Thanks 1
Posted

@witch, it's still rather difficult to respect that structure given that a senior management team comprised solely of people from one profession makes no sense and can't work.

 

Naturally there does need to be a hierarchy at the end of the day, but when you're the sole expert in a particular domain it's not unreasonable to expect SLT to justify themselves every once in a while. The IT industry as a whole wasn't created just for them, has standards of its own which exist for very good reasons and rightly demands some degree of respect for them.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...