GuyJD Posted October 4, 2016 Posted October 4, 2016 I have a bit of an issue, our head teacher has signed up for some new online service that connects to our SIMS database to read and write data, to get it up and running the external company need remote access to our admin server, now obviously I'm really not happy with this but the head insists it has to happen. So my question is, what is the best way to allow them RDP access to the server to install and configure their software but without giving them full admin rights to the server? Because of LGfL's amazing policy on not allowing shared remote access, services like Logmein or TeamViewer are not an option, I'm going to be blind to what is going on while they install so obviously I'm a bit concerned.
cpjitservices Posted October 4, 2016 Posted October 4, 2016 Can you set up a temporary VPN and let them use Remote Desktop under a restricted admin account ? To be honest its not too much of a problem letting them in, managing hundreds of companies as we do we get these requests quite often from the likes of Sage etc. Its fairly safe to let them in, we set up an account for example called manager and put an expiration on the password to 24 hours. We give them install rights but thats about it. We temporarily open 3389 on the router and let them RDP in if we cant use TeamViewer or LogMeIn. Usually these companies use TV or Log Me In Quick Support.
GuyJD Posted October 4, 2016 Author Posted October 4, 2016 We have to use Cisco AnyConnect which will set up the VPN and I can manage the account that they will use to set up the VPN as well as the account they use to log in to the server, I guess I'm just over analsing the situation as it's quite a well respected company that want access.
DavidYoung Posted October 5, 2016 Posted October 5, 2016 You can use Teamviewer or other similar services through LGfL if you get the headteacher to agree to the declaration on the support site > My Account > HT Declarations. This will allow you to unblock individual applications through Webscreen. 1
mfluder Posted September 11, 2018 Posted September 11, 2018 Thanks for this, I'm looking into remote desktop now.
AlanD Posted September 11, 2018 Posted September 11, 2018 To be honest its not too much of a problem letting them in, managing hundreds of companies as we do we get these requests quite often from the likes of Sage etc. Its fairly safe to let them in, The issue is not whether it is safe....the issue is with "does it comply with GDPR?" And allowing any Tom/Dick/Harry access which may allow them to see personal data on your systems is almost certainly not allowed. You might not give them access to a SIMS logon - but if the can simply copy a database and the data isn't encrypted it has the potential for a data breech. In practice...of course - you are going to have to give some access to allow them to get the job done...but I think these days you would probably need to show close supervision and monitoring to prevent such a breech. It's likely - that the current breech that BA experienced was "external contractors" working on their web sites leaving in place something which allowed an easy hack. External access by companies is always going present a GDPR risk - especially if they have administration rights... 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now