Jump to content

HelpDesk / IT Technicians day to day account vs Domain Admins group.


Recommended Posts

Posted

So what is the consensus view here about using your domain admin account to read email, surf the web and access the shared documents folders?

 

What reference points do you use to justify that decision?

 

Particularly interested in hearing from those is teams of 2+ or with large/multiple sites.

 

p.

Posted

As a loan tech/NM I always used a standard staff login and only used my domain admin credentials when necessary.

 

It stops me making mistakes... making me think twice before I shoot. And it also means that I see the world as everyone else does... often detecting problems before the majority of staff were aware.

Posted (edited)
I generally just use a local admin account on the PC i'm using, which can depend. I leave the domain admin account alone unless i actually need it. Edited by Patrick
Posted
I was taught many years ago to never use your domain admin account unless you need to, you should always have a restricted user account for your day-to-day work. The restricted account would probably still have the rights to install software etc. onto a local machine but not do anything on a domain level.
Posted (edited)

I sit at my desk with my main profile, which is a domain administrator. This is where I spend 90% of my day.

 

I have a "tech" profile which I use anywhere else in the building to perform administrative tasks such as installing software. This isn't bogged down with the roaming data from my main account.

 

I have a "staff" and "student" accounts in order to do testing in classrooms to see things as they see it when trying to replicate a problem.

 

My technician has the same setup, because in order to do his job he needs administrator access. There's only two of us, he needs to be able to tackle the majority of issues. He has no access to the actual domain Administrator account, or any physical or remote access to servers except the WDS server in order to authorise computers to be reimaged.

Edited by Mako
Posted

We've got 8 IT staff across the trust we all have two accounts - one for day to day use and one for administrative purposes.

 

It prevents "click-oops" moments for one - as you're generally a little more careful while using your admin account. We've all granted local admin rights to our own machines to our standard accounts, but the day to day stuff is all done via our normal accounts. Anything domain based is done by RDP on a server, using our admin accounts.

Posted

We have 3 accounts; day to day bog standard account, PC admin account and Server account. This is the same for the Tech and Deputy IT Manager, albeit the tech's admin accounts are building up permissions as we introduce him to systems.

 

Shouldn't matter if you are a one man band or department of 1000, best practice is NOT to use an admin account, whether local or domain, for generally use but to elevate as needed. Any arguments I have ever heard against this are justifications and come down to "saving time" and it "being easier".

 

We do have dummy student and teacher accounts for testing but they do not have any access to anything special.

 

There is also the argument for "eating your own dog food", generally running the same level as your users so you will hit the same issues they do, forcing you to confront them. To me this is more arguable either way.

  • Thanks 2
Posted

Two of us here, we each have three accounts.

  • Regular staff user account. This is what we're logged into our PCs with, for day to day work, web browsing, email, etc. No admin privileges, just like regular staff (for both security and dogfooding reasons).
  • A named account which has local admin privileges on domain client machines. This is what we'd use when administering client machines, or needing to do 'Run as another user' jobs in a standard user session (including our own). These accounts are prevented from logging into any servers.
  • A named domain admin account (member of the Domain Administrators group). This is what we use when doing admin tasks on servers (usually via an RDP session). This includes day to day sysadmin tasks such as copying files into or out of user areas, managing GPOs and AD, etc. We make a point of not logging into clients with these, and not doing any web browsing with them.
  • All client machines have the local administrator account configured using LAPS. We only really use these if a machine is unable to reach the domain for some reason.

  • Thanks 1
Posted (edited)
We have 3 accounts; day to day bog standard account, PC admin account and Server account. This is the same for the Tech and Deputy IT Manager, albeit the tech's admin accounts are building up permissions as we introduce him to systems.

 

Shouldn't matter if you are a one man band or department of 1000, best practice is NOT to use an admin account, whether local or domain, for generally use but to elevate as needed. Any arguments I have ever heard against this are justifications and come down to "saving time" and it "being easier".

 

We do have dummy student and teacher accounts for testing but they do not have any access to anything special.

 

There is also the argument for "eating your own dog food", generally running the same level as your users so you will hit the same issues they do, forcing you to confront them. To me this is more arguable either way.

 

Please people follow the 2 above examples. right click run as administrator is only a click away.

Edited by gaz350b
Posted

We have a "normal" account (no GPO restrictions and local admin on our own workstations) that we use day to day and elevate for anything needing admin rights on other machines (for remote server admin tools, I run servermanager.exe as a domain admin account using runas.exe, so all the tools within open automatically as domain admin)

 

Wouldn't do general browsing etc on a domain admin account as they have full control rights to everything on the network, get hit by something nasty while browsing and you've potentially trashed everything - vs do the same with your normal account and you lose your documents and the PC.

Posted
I use a local admin account, with no password commonality to other workstations, on my workstation. I only use a domain admin account for server work, usually via RDP, and I use my standard user account if I need to get to a share or similar. Not best practice, but has been okay and I'm aware of the limitations. Would be better to elevate the account when needed, but that can go on the list of 'at some point'.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...