Jump to content

Recommended Posts

Posted (edited)

What level of access do you give to local authority SIMS support into your sims servers?

 

I've just changed my domain password and had a message saying that they can't log in. Full domain admin access seems a little overkill.

Edited by MkII
Posted
I work for a local authority SIMS support unit and most schools choose to give us a full domain admin account as it is easier for them. Generally what we need is a user that is local admin on the SIMS server(s) {If the functions are split over multiple machines} and another service account to use for SOLUS3 which is a local admin on all workstations needing SIMS/FMS/Discover {though they could be the same account but this account doesn't need login privelages}. The advantage of having a domain admin account is when analysing problems with SIMS/SOLUS/etc. there is generally a lot more that can be done without disrupting users and support staff in school, whereas just a local admin account on the SIMS server would mean we need local IT support to continually grant us access {by whatever means} to workstations with issues that need resolving.
  • Thanks 1
Posted
Too much access, is what. They (same LA I think) don't have the domain admin account, but quite a high level one, and that's how they want it. That will end now - I have disabled the account and will fully audit its abilities. They have no need whatsoever to get to where they can at present. I will also log every access request, enable then disable the account. I just found it left logged on remotely - they had no right or reason to be there. Bye!
  • Thanks 1
Posted

We only give them a server admin account - they know the account that SOLUS uses on the workstations though. I do let them have access to the server at their convenience, and don't watch them whilst they are working, but they always e-mail me to tell me what they are going to do and when.

We don't tend to get them involved in supporting the user workstations: if its a single user/workstation, redeploy or re-image usually fixes it, and if its global they can have a temp local admin on a test machine.

  • Thanks 1
Posted
I work for a local authority SIMS support unit and most schools choose to give us a full domain admin account as it is easier for them. Generally what we need is a user that is local admin on the SIMS server(s) {If the functions are split over multiple machines} and another service account to use for SOLUS3 which is a local admin on all workstations needing SIMS/FMS/Discover {though they could be the same account but this account doesn't need login privelages}. The advantage of having a domain admin account is when analysing problems with SIMS/SOLUS/etc. there is generally a lot more that can be done without disrupting users and support staff in school, whereas just a local admin account on the SIMS server would mean we need local IT support to continually grant us access {by whatever means} to workstations with issues that need resolving.

 

Thanks for that. Ours never access workstations that I've ever known.

Posted
A lot of the workstation access is to collect logs from Capita products or to look at MS Office issues, usually requiring clearing temp files and the like. We've also connected MMC from the server to workstations to look at running services for SOLUS and firewall configurations, sometimes to look at SIMS.ini and connect.ini files or give specific users the SIMS Multinstance shortcut in their start menu on their workstation. There are other things we connect to workstations for on a fairly regular basis but that gives you a flavor of what support we do with the access.
Posted
Just tested the account - pulled off all admin capabilities and left it as a Domain User only. Looks like they can get to everything they need, UAC blocks the rest, and no possibility of accessing any shares beyond the S drive. My DP hat can be adorned with a shiny new badge.
  • Thanks 1
Posted
A lot of the workstation access is to collect logs from Capita products or to look at MS Office issues, usually requiring clearing temp files and the like. We've also connected MMC from the server to workstations to look at running services for SOLUS and firewall configurations, sometimes to look at SIMS.ini and connect.ini files or give specific users the SIMS Multinstance shortcut in their start menu on their workstation. There are other things we connect to workstations for on a fairly regular basis but that gives you a flavor of what support we do with the access.

 

Ours do nothing like that. I think the local authority only give their own support teams an account that gives local admin access to workstations only.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...