psydii Posted November 13, 2018 Posted November 13, 2018 So what is the consensus view here about using your domain admin account to read email, surf the web and access the shared documents folders? What reference points do you use to justify that decision? Particularly interested in hearing from those is teams of 2+ or with large/multiple sites. p.
elsiegee40 Posted November 13, 2018 Posted November 13, 2018 As a loan tech/NM I always used a standard staff login and only used my domain admin credentials when necessary. It stops me making mistakes... making me think twice before I shoot. And it also means that I see the world as everyone else does... often detecting problems before the majority of staff were aware.
Patrick Posted November 13, 2018 Posted November 13, 2018 (edited) I generally just use a local admin account on the PC i'm using, which can depend. I leave the domain admin account alone unless i actually need it. Edited November 13, 2018 by Patrick
noelmm Posted November 13, 2018 Posted November 13, 2018 I was taught many years ago to never use your domain admin account unless you need to, you should always have a restricted user account for your day-to-day work. The restricted account would probably still have the rights to install software etc. onto a local machine but not do anything on a domain level.
Mako Posted November 13, 2018 Posted November 13, 2018 (edited) I sit at my desk with my main profile, which is a domain administrator. This is where I spend 90% of my day. I have a "tech" profile which I use anywhere else in the building to perform administrative tasks such as installing software. This isn't bogged down with the roaming data from my main account. I have a "staff" and "student" accounts in order to do testing in classrooms to see things as they see it when trying to replicate a problem. My technician has the same setup, because in order to do his job he needs administrator access. There's only two of us, he needs to be able to tackle the majority of issues. He has no access to the actual domain Administrator account, or any physical or remote access to servers except the WDS server in order to authorise computers to be reimaged. Edited November 13, 2018 by Mako
HPlum78 Posted November 13, 2018 Posted November 13, 2018 When we say Domain Admin account are we referring to an account that is a member of the Domain Admins group? Or a more priveledged account?
korifugi Posted November 13, 2018 Posted November 13, 2018 We've got 8 IT staff across the trust we all have two accounts - one for day to day use and one for administrative purposes. It prevents "click-oops" moments for one - as you're generally a little more careful while using your admin account. We've all granted local admin rights to our own machines to our standard accounts, but the day to day stuff is all done via our normal accounts. Anything domain based is done by RDP on a server, using our admin accounts.
TechMonkey Posted November 13, 2018 Posted November 13, 2018 We have 3 accounts; day to day bog standard account, PC admin account and Server account. This is the same for the Tech and Deputy IT Manager, albeit the tech's admin accounts are building up permissions as we introduce him to systems. Shouldn't matter if you are a one man band or department of 1000, best practice is NOT to use an admin account, whether local or domain, for generally use but to elevate as needed. Any arguments I have ever heard against this are justifications and come down to "saving time" and it "being easier". We do have dummy student and teacher accounts for testing but they do not have any access to anything special. There is also the argument for "eating your own dog food", generally running the same level as your users so you will hit the same issues they do, forcing you to confront them. To me this is more arguable either way. 2
jthompson Posted November 13, 2018 Posted November 13, 2018 Two of us here, we each have three accounts. Regular staff user account. This is what we're logged into our PCs with, for day to day work, web browsing, email, etc. No admin privileges, just like regular staff (for both security and dogfooding reasons). A named account which has local admin privileges on domain client machines. This is what we'd use when administering client machines, or needing to do 'Run as another user' jobs in a standard user session (including our own). These accounts are prevented from logging into any servers. A named domain admin account (member of the Domain Administrators group). This is what we use when doing admin tasks on servers (usually via an RDP session). This includes day to day sysadmin tasks such as copying files into or out of user areas, managing GPOs and AD, etc. We make a point of not logging into clients with these, and not doing any web browsing with them. All client machines have the local administrator account configured using LAPS. We only really use these if a machine is unable to reach the domain for some reason. 1
gaz350b Posted November 13, 2018 Posted November 13, 2018 (edited) We have 3 accounts; day to day bog standard account, PC admin account and Server account. This is the same for the Tech and Deputy IT Manager, albeit the tech's admin accounts are building up permissions as we introduce him to systems. Shouldn't matter if you are a one man band or department of 1000, best practice is NOT to use an admin account, whether local or domain, for generally use but to elevate as needed. Any arguments I have ever heard against this are justifications and come down to "saving time" and it "being easier". We do have dummy student and teacher accounts for testing but they do not have any access to anything special. There is also the argument for "eating your own dog food", generally running the same level as your users so you will hit the same issues they do, forcing you to confront them. To me this is more arguable either way. Please people follow the 2 above examples. right click run as administrator is only a click away. Edited November 13, 2018 by gaz350b
Katy Posted November 13, 2018 Posted November 13, 2018 We have a "normal" account (no GPO restrictions and local admin on our own workstations) that we use day to day and elevate for anything needing admin rights on other machines (for remote server admin tools, I run servermanager.exe as a domain admin account using runas.exe, so all the tools within open automatically as domain admin) Wouldn't do general browsing etc on a domain admin account as they have full control rights to everything on the network, get hit by something nasty while browsing and you've potentially trashed everything - vs do the same with your normal account and you lose your documents and the PC.
3s-gtech Posted November 13, 2018 Posted November 13, 2018 I use a local admin account, with no password commonality to other workstations, on my workstation. I only use a domain admin account for server work, usually via RDP, and I use my standard user account if I need to get to a share or similar. Not best practice, but has been okay and I'm aware of the limitations. Would be better to elevate the account when needed, but that can go on the list of 'at some point'.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now