Get2theChoppa Posted September 5, 2013 Posted September 5, 2013 Bit random... I was approached by SLT and asked to give admin level rights (as in admin password to one designated memeber of staff) so in case when I am not onsite or if I die all of a sudden then they have a way of gaining access to the network? Whats your view on this? Would you? If Yes? why? If No? Why?
plexer Posted September 5, 2013 Posted September 5, 2013 There needs to be a documented procedure in place for this and if you are the only IT support person on site it should be something along the lines of username/password secured in school safe. Ben 1
creese Posted September 5, 2013 Posted September 5, 2013 Why not just have the password in a sealed envelope in a safe? 1
jamesreedersmith Posted September 5, 2013 Posted September 5, 2013 No but an account details sealed in the safe for "emergency" use only. 1
Devontechie Posted September 5, 2013 Posted September 5, 2013 As above, admin password in a sealed in the safe 1
RichB Posted September 5, 2013 Posted September 5, 2013 We have all admin related passwords on an encrypted memory stick in the safe. Ask him if the system went down and all the data went and he wanted someone to blame his name would be in the hat also, as he has admin access! 1
jallsop Posted September 5, 2013 Posted September 5, 2013 Paper copies in an envelope which requires destroying to open, in a fire proof safe.
FN-GM Posted September 5, 2013 Posted September 5, 2013 Why not just have the password in a sealed envelope in a safe? If you laminate the envelope leaving plenty of empty plastic along all edges you will be able to see it hasn't been tampered with.
Marci Posted September 5, 2013 Posted September 5, 2013 Create a unique separate account with administrator privileges... that way any activity on it can be tracked and seperated from your actual administrator account. As per everyone else - sealed destructive envelope in safe or encrypted memory stick in safe, and presuming all staff don't have access to the safe, a specific signing out sheet left with whoever is in charge of the safe which must be completed whenever the details are removed / used. 1
elsiegee40 Posted September 5, 2013 Posted September 5, 2013 Create a unique separate account with administrator privileges... that way any activity on it can be tracked and seperated from your actual administrator account. As per everyone else - sealed destructive envelope in safe or encrypted memory stick in safe, and presuming all staff don't have access to the safe, a specific signing out sheet left with whoever is in charge of the safe which must be completed whenever the details are removed / used. This. Nobody gets my password! 1
Get2theChoppa Posted September 5, 2013 Author Posted September 5, 2013 This. Nobody gets my password! lol would love to know your rationale...
john Posted September 5, 2013 Posted September 5, 2013 lol would love to know your rationale... As a lot of SLT are not IT Professionals and think that just because BitCommet works well at home that it won't harm to have it on the school computer or the 100 stupid add-on toolbars in IE etc... Seeing how some SLT I have worked with (not all) use a computer and click blindly and randomly, I'd expect a network to last all of 5 minutes with them! 1
TechMonkey Posted September 5, 2013 Posted September 5, 2013 (edited) lol would love to know your rationale... For the same reason I tell staff not to give anyone, even me, their password. It is my account so anything that happens on it is my responsibility. If I give out my password to anyone, even SLT, then that increases risk of something happening but doesn't decrease my responsibility. Odd response from an IT bod really. Edited September 5, 2013 by TechMonkey 1
Jawloms Posted September 5, 2013 Posted September 5, 2013 lol would love to know your rationale... Why would they need it? Passwords are like underwear - change them regularly and never share them. 1
Jamman960 Posted September 5, 2013 Posted September 5, 2013 When I first started here about 3 of the SLT had administrative access or local admin passwords purely because they were in senior positions, one of them would buy and install printers for staff and install random toolbars(sparklebox!) or software upon request despite me asking him not to... now I'm the only one with admin access - as with most others a password list is in the safe along with full documentation. 1
Ephelyon Posted September 5, 2013 Posted September 5, 2013 We have a separate account (the domain's default Administrator account) with its password stored in the safe, but TBH I don't really class this as "giving SLT admin access". To my mind that would be more like what @Jamman960 is referring to.
pcstru Posted September 5, 2013 Posted September 5, 2013 Yes/No - depends which member of SLT wanted it! Some would worry me more than others. We are much the same as others in that our contingency is a copy in the safe where we keep a copy of the credentials for the lastpass account which holds all (probably not quite yet) the other passwords. Our backup to that is a book.
witch Posted September 5, 2013 Posted September 5, 2013 Explain the issue very carefully, including the worst-case-scenario and the "password in a safe" solution. Then, if they insist -explain some more, detail your objections and document your explanation in an email or something so it is written down for future reference If they still insist - create the separate admin acct as detailed above -perhaps restricting them to super-user?
Ephelyon Posted September 5, 2013 Posted September 5, 2013 That's another point; for what many of them would ask for, full Enterprise Admin access may not be needed and you may well be able to "get away" with an account that has local admin access to all workstations plus e.g. full control permissions cascaded downwards from the root of your file servers' data volumes.
plexer Posted September 5, 2013 Posted September 5, 2013 Just ask them to explain why they think they need this level of access. Ben
jmak Posted September 5, 2013 Posted September 5, 2013 Why would they need it? Passwords are like underwear - change them regularly and never share them. You see, I've never shared my password, cos I could be blamed for anything done under those account details, but now you've put it like that, it sounds fun 1
elsiegee40 Posted September 5, 2013 Posted September 5, 2013 (edited) This. Nobody gets my password! lol would love to know your rationale... There is history... ... involving a headteacher, a holiday, a password, a safe and a third party supplier... ... it was the last straw. Don't believe it would never happen @Get2theChoppa. I had been in the industry for over 20 years when it did Protect yourself and your network. Edited September 5, 2013 by elsiegee40 2
witch Posted September 5, 2013 Posted September 5, 2013 Just ask them to explain why they think they need this level of access. Ben Well, you can ask, but as they are SLT they outrank you and can do what they like. It is neither "your" network nor "your" password so the only thing you can do is tell them why it is not a good idea and ask them what they are thinking that they might need to do when you are not there 1
6Foot2 Posted September 5, 2013 Posted September 5, 2013 Why would they need it? Passwords are like underwear - change them regularly and never share them. [Old] Thread with relevant pictures/posters: Link: http://www.edugeek.net/forums/jokes-interweb-things/42998-passwords-like-underwear.html 1
Ephelyon Posted September 5, 2013 Posted September 5, 2013 @witch, it's still rather difficult to respect that structure given that a senior management team comprised solely of people from one profession makes no sense and can't work. Naturally there does need to be a hierarchy at the end of the day, but when you're the sole expert in a particular domain it's not unreasonable to expect SLT to justify themselves every once in a while. The IT industry as a whole wasn't created just for them, has standards of its own which exist for very good reasons and rightly demands some degree of respect for them.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now