petben Posted December 13, 2018 Posted December 13, 2018 Hello, back in the day staff were local admins of their computers to get SIMS to work properly, I imagine (?) this is now not the case. Can anyone advise/forsee any issues making staff users of their workstations? Staff in the admin office will complain I am sure as they are currently setup with full unfettered access, but why they need this level of access I am not sure. Thanks
deKay Posted December 13, 2018 Posted December 13, 2018 No issues. SIMS works fine (and has done for a decade or more) without admin rights.
synaesthesia Posted December 13, 2018 Posted December 13, 2018 Absolutely - no staff should have local admin rights period. Too risky, far too much to go wrong. 2
atcoates Posted December 13, 2018 Posted December 13, 2018 To be honest years a go you could probably be fine letting people have control over their pcs. These days one wrong click can ransomware a whole network. Out of my eight schools the only user that has any admin rights is me. The rest are locked down! If the network is set up properly and software is distributed centrally there really shouldn't be any need for users to have that level of access. It's a modern day recipe for disaster!
mikkydoos Posted December 13, 2018 Posted December 13, 2018 You used to need modify permissions on a few files in c:\progra~1\Sims directory... but not for ages. Get them un-admin'd
jthompson Posted December 13, 2018 Posted December 13, 2018 TBH, any 'problems' you encounter after lowering their privileges are more likely to be problems for you right now. Best to make the change, discover them and work out the solutions. The update mechanisms for some software may be broken for them. You may find that most of your work off the back of making the change will be ironing out software distribution. If you do software deployment of MSIs via Group Policy, you can if you want put them under the user configuration half, so that they're available for users to install from Add/Remove Programs in the Control Panel.
rosslaing Posted December 14, 2018 Posted December 14, 2018 (edited) No staff should have admin access, just creates more work for us in the long term. Id rather I was the one having to do whatever needs done on the machines with Admin access, more control over the environment, less troubles long term. Work the problems when things need admin access, and, for me anyway, if a bit of software requires admin access to run, then it is poorly designed, obviously for home users, and not going anywhere near the systems. Edited December 14, 2018 by rosslaing
petben Posted December 14, 2018 Author Posted December 14, 2018 I posed the Q to Capita and they replied: Most users require no additional rights to their workstations to run SIMS.The exceptions to this are: - Exams Officer - Timetabler - Finance These users require at least full control permissions over the following files/folder locations (including sub folders): - C:\Windows\SIMS.ini - C:\Program File (x86)\SIMS or C:\Program Files\SIMS Is this really necessary? I imagine some GPO folder permissions things can be done if required.
Arthur Posted December 14, 2018 Posted December 14, 2018 Is this really necessary? No, because modifications made by SIMS to those files when running under a standard user account will be automatically redirected to %LocalAppData%\VirtualStore by Windows. If Finance and Exams need anything changed in their INI files I usually make these changes as an administrator and then SIMS works fine for any user that logs onto their computers from that point forward. If they have any INI files in their VirtualStore folders I delete these too, so the other one takes precedence.
3s-gtech Posted December 14, 2018 Posted December 14, 2018 (edited) We installed SIMS across the site in 2006 - staff didn't need admin permissions on the workstations even then. EDIT: we did use SIMSPERM.bat which opened up write permissions on the SIMS install folders, but nothing more. Edited December 14, 2018 by 3s-gtech
MatthewL Posted December 14, 2018 Posted December 14, 2018 We removed admin privileges years ago and it reduced the amount of calls for problems due to users not been able to break stuff, we spent the time sorting out GPO's so that it would amend the relevant permissions on folders so all we had to do was join to domain, install software and away we went. The calls we got were genuine ones when things needed installing and it allowed us to keep tabs what users were doing with software etc. Get a PC and restrict it down, see what doesn't work, get it working, test with a couple of users and then go do the lot. Well you can do it all via GPO.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now