Jump to content

Recommended Posts

Posted
I'm interested to know what approaches you take to protect against admin users that go 'bad'. I'm thinking of this from both a Windows server and Google admin point of view. As an example, for GSuite, we have three super users. Any one of them, at any time could lock the others out and have exclusive control. Ultimately there appears there will always be a point where you rely on trust, but I'm wondering if there are reasonable steps that a 'Super Super user' account can be left dormant and require at least two sign-offs to access. Is such a concept considered as part of any formal qualifications?
Posted (edited)

I believe it's simply an element of your role and responsibility and managed risk. If your other users require that level of access due to their role then make sure it's clearly defined. The only way around it would be delegated access so that somewhere you still have total control of the system, which would cause a single point of failure in the event that something critical happened to the super user and the knowledge of access was lost.

 

In the same vein, a site manager with physical access to the entire building could go "bad" and unlock the server room and start pulling wires. Or simply just cut the power to the building if you had a more secure server setup.

 

There are just some things you don't do, and if those things are done I'm sure there'd be serious ramifications (likely criminal?) for that individual.

Edited by Mako
Posted
I agree it's a risk management situation and for sure we are considering activities that should not happen and would be illegal. The delegated route is something I've considered, but on the flip side, with having three users, with appropriate notifications in place, the other two would be aware of odd activity very quickly. Three accounts on the other hand is three time the risk! Any probably the bigger risk is more one of those accounts being hacked and misused, rather than the one of the three trusted users going 'bad'.
Posted

You have identified a risk so you should now plan on how to mitigate that risk.

 

One solution would be to delegate the access and create a super user account, the details of which the other admins do not know (and due to delegation they cannot lock out or tamper with). The details of this should be added to the disaster recovery documentation and placed in a safe to which the other admins do not have access, such as the headteacher's safe.

 

In the event that something happens to you, the headteacher responsible would have access to the documentation that would detail how to continue and could provide that information solely to the person taking over. The risk is mitigated as your "risky" admins are still out of the loop and only those responsible have access to the information.

 

There's probably flaws even with that but it's something I just thought of to tailor to your situation.

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...