Jump to content

Recommended Posts

Posted

We obviously take domain admin rights and passwords very seriously and guard the passwords and rights as much as is possible but....

 

As a third party support provider, if one of our schools (i.e. the Head) requested the domain administrator password, we would feel obliged to hand it over as the server and all of the equipment belongs to the school and we feel that we would have no rights to withhold it which I think is right.

 

Has anyone faced this issue before and are you aware of any legal rights regarding domain admin passwords?

Posted
A copy of all network passwords should be kept in a sealed envelope in the school safe regardless of who provides the ICT Support, in-house or 3rd party.
Posted

Are you a company of many staff where the likelihood one person who knows it is run over by a bus while the other is holiday is slim?

 

From a security point of view, keeping that password in as few places as possible is sensible. However, it is their network and not yours. If they decide they want to wrest control from you, then you don't have much choice... even if you do end up clearing up the mess afterwards.

Posted

Indeed, as you say, the network actually belongs to the school. If the head requests the domain admin password, you have to hand it over. However, there is a possible exception here - it depends on the contract you have with them. If the contract says that the domain admin password will only be handed over on termination of the contract, then that would mean you don't have to hand it over unless they are terminating that contract.

 

That said, the passwords should be stored somewhere at the school in a safe anyway. Just in case.

Posted
If the school want the password then i'm fairly sure it would be wise to provide it. If an individual wants it then you need to speak to your designated contact. If the contact is the business manager then they might not want to HT to have the password.
Posted

Thanks all for your comments - this is exactly what we thought.

@localzuk - in your opinion then, if the contract (or service level agreement) doesn't specifically mention withholding passwords until termination of contract, that the school should have the right to request it?

Posted
I need to make it clear that in your situation that the only person I would release it to be the Head of the establishment. You don't just hand it over to the secretary who has been asked to call you...
Posted
Does anyone know of any law regarding the ownership of passwords within the UK? I would have thought this would have cropped up more often but I can't find many references to this, especially in the UK.
Posted
There needs to be some sort of policy that defines its use and the support required to rectify or damage limit any unauthorized changes. Its use has to be proportional for the reasons for its use.

If company x come in to install software and they dont go through the correct procedure and just give the admin details to company x to do it themselves and make a total clarkson of it. Situations like this needs to be in black and white.

I think you get the idea.

 

I do understand your point and there should possibly be a disclaimer when handing over the password absolving the company of mistakes made by third parties but should this not be explicitly stated within the service level agreement prior to the beginning of the contract?

Posted (edited)

Summary?

Yes, you *have* to give the password over unless you have a darned good reason not to.

Yes, the school has to make an effort in saying that should anything go wrong as a result then you are not held liable and that the school has to cough up some cash to get it fixed.

Yes, there is a risk that this could be that the school is moving to someone else, or at least are checking up on the quality of what you are doing.

 

Without wanting to go into contract law (as I have not seen your contract with the school so cannot comment on specifics) the general principles of situations like this goes as follows.

 

  1. You are an employee, contractor or other person designated by the school to provide a given service and are obliged to provide that service until your contract is terminated or expires.
  2. As part of that contract you are dealing with both equipment and information that is either owned or the responsibility of the school (where the school is a recognised body).
  3. Instructions on your work will be given by other employees, contractors or other persons designated by the school, and these people, including their roles and responsibilities, should have already been agreed by you and the school.
  4. If these people have not been agreed between you and the school then you have to at least respond to the legal representatives of the school, i.e. the Head and whoever has signed the contract on behalf of the Head (e.g. the Business Manager).
  5. Any usernames, passwords, account information, etc will be the property of the school and control can be requested by the school unless
    a) covered by areas of your contract,
    b) it would be in breach of any law of the land or
    c) you have reason to believe it would affect the outcome of any disciplinary or grievance.

 

If a) then you state the areas of the contract and then leave it to your lawyers and the school's lawyers to work out if the clause was strictly legal and can be upheld ... if it can't then you have to hand things over, if it can then it will get even murkier and you need to make sure you have a *really* good lawyer.

 

If b) then you need to report this to the relevant authorities ... I can't think of any particular examples at the moment other than the access requested would also grant access to areas that the person has not right to see or information they have no right to process, e.g. data about children not in that school (it would raise the question about why it is on that system ... but stranger things have happened).

 

If c) then you need to make someone relevant aware, usually the Line Manager of the person who has made the request. If it is the BM or similar then you go to the Head and get agreement (in writing / email) to say that the accounts can be released and if it is the Head then you go to the Chair of Governors and/or LA about it and get their sign off.

 

Looking at it from the relationship between you and the school you have a few scenarios that might be affecting your judgement on this.

 

There is the (valid) concern that by giving out the account then the Head will fiddle and that will break things, and then they will try to blame you. The way around this is to suggest you give an administrative account to the Head, but not the main Administrator ... so you can prove which account was used to do the damage. Make sure you have the relevant level of logging in place and ensure you have evidence of this being in place. This creates accountability for the school as well.

 

You may have a concern that the school is getting a 3rd party to do other things rather than pay you to do it ... and you are worried that they could mess things up. Please see the above answer. Unless you have an exclusive contract you cannot really restrict if another company does work too ... only make sure you get acknowledgement that if they break something and you have to fix it then the rates you charge will be £xxx per 1/2 day ... and the minimum charge will be 2x 1/2 days.

 

You may have a concern that the school wants to replace you with a different support company. That is at the school's discretion, and is down to contract management. Your contract may have a minimum term clause which would mean the school has to pay you even if they don't use your services. If they are getting someone else in they you must insist that the school gives notice on your contract and you get the full fee out of them, but make sure that they relinquish any rights to draw on your services ... this is messy, so again I would say speak to a lawyer who deals in this side of contract law.

 

Looking at if rom the school's side now.

 

The School should have control over its systems and, as part of BCDR at least, be able to lay their hands directly on everything they need without requiring you to be involved. This covers them if you go under, if all your staff leave, if there is a contractual dispute, etc. It is a minimum expectation of the school if they are doing things correctly.

 

The school might want to have an independent audit of their systems, so that they can work on the strategic plan for the school and the technology they need / will use. They will want this to be independent of external suppliers / contractors as they have to show best value, need to audit the quality of your work and make sure any recommendations for change or growth are not overshadowed by any commercial conflicts (i.e. you want to get the most business out of the school and get as much of their money as you can). Whilst you might be as honest as the day is long, the school *has* to treat you as they would any other supplier and be careful. This is nothing personal ... it is due process and good practice.

 

So, that outlines the issue from all sides.

Edited by GrumbleDook
Tyops ... it is late!
  • Thanks 3
Posted

Rather than hand over the password to your existing domain admin account, I would create a new one for the head.

Couple this with enabling auditing so you can track what is done by the account.

 

Then tell him he can have the password but fixing anything that gets broken is chargable.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...