MkII Posted May 17, 2018 Posted May 17, 2018 (edited) What level of access do you give to local authority SIMS support into your sims servers? I've just changed my domain password and had a message saying that they can't log in. Full domain admin access seems a little overkill. Edited May 17, 2018 by MkII
TwistedHelixis Posted May 17, 2018 Posted May 17, 2018 Our LA insist on DA access to our primary school sims servers, but I block their remote access, so they can only get on while I am watching. 1
Esteban_Child_of_the_Sun Posted May 17, 2018 Posted May 17, 2018 I work for a local authority SIMS support unit and most schools choose to give us a full domain admin account as it is easier for them. Generally what we need is a user that is local admin on the SIMS server(s) {If the functions are split over multiple machines} and another service account to use for SOLUS3 which is a local admin on all workstations needing SIMS/FMS/Discover {though they could be the same account but this account doesn't need login privelages}. The advantage of having a domain admin account is when analysing problems with SIMS/SOLUS/etc. there is generally a lot more that can be done without disrupting users and support staff in school, whereas just a local admin account on the SIMS server would mean we need local IT support to continually grant us access {by whatever means} to workstations with issues that need resolving. 1
3s-gtech Posted May 17, 2018 Posted May 17, 2018 Too much access, is what. They (same LA I think) don't have the domain admin account, but quite a high level one, and that's how they want it. That will end now - I have disabled the account and will fully audit its abilities. They have no need whatsoever to get to where they can at present. I will also log every access request, enable then disable the account. I just found it left logged on remotely - they had no right or reason to be there. Bye! 1
Linfit Posted May 17, 2018 Posted May 17, 2018 We only give them a server admin account - they know the account that SOLUS uses on the workstations though. I do let them have access to the server at their convenience, and don't watch them whilst they are working, but they always e-mail me to tell me what they are going to do and when. We don't tend to get them involved in supporting the user workstations: if its a single user/workstation, redeploy or re-image usually fixes it, and if its global they can have a temp local admin on a test machine. 1
MkII Posted May 17, 2018 Author Posted May 17, 2018 I work for a local authority SIMS support unit and most schools choose to give us a full domain admin account as it is easier for them. Generally what we need is a user that is local admin on the SIMS server(s) {If the functions are split over multiple machines} and another service account to use for SOLUS3 which is a local admin on all workstations needing SIMS/FMS/Discover {though they could be the same account but this account doesn't need login privelages}. The advantage of having a domain admin account is when analysing problems with SIMS/SOLUS/etc. there is generally a lot more that can be done without disrupting users and support staff in school, whereas just a local admin account on the SIMS server would mean we need local IT support to continually grant us access {by whatever means} to workstations with issues that need resolving. Thanks for that. Ours never access workstations that I've ever known.
Esteban_Child_of_the_Sun Posted May 17, 2018 Posted May 17, 2018 A lot of the workstation access is to collect logs from Capita products or to look at MS Office issues, usually requiring clearing temp files and the like. We've also connected MMC from the server to workstations to look at running services for SOLUS and firewall configurations, sometimes to look at SIMS.ini and connect.ini files or give specific users the SIMS Multinstance shortcut in their start menu on their workstation. There are other things we connect to workstations for on a fairly regular basis but that gives you a flavor of what support we do with the access.
3s-gtech Posted May 17, 2018 Posted May 17, 2018 Just tested the account - pulled off all admin capabilities and left it as a Domain User only. Looks like they can get to everything they need, UAC blocks the rest, and no possibility of accessing any shares beyond the S drive. My DP hat can be adorned with a shiny new badge. 1
MkII Posted May 17, 2018 Author Posted May 17, 2018 A lot of the workstation access is to collect logs from Capita products or to look at MS Office issues, usually requiring clearing temp files and the like. We've also connected MMC from the server to workstations to look at running services for SOLUS and firewall configurations, sometimes to look at SIMS.ini and connect.ini files or give specific users the SIMS Multinstance shortcut in their start menu on their workstation. There are other things we connect to workstations for on a fairly regular basis but that gives you a flavor of what support we do with the access. Ours do nothing like that. I think the local authority only give their own support teams an account that gives local admin access to workstations only.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now