Jump to content

Recommended Posts

Posted

Hi,

 

At our school we have office 365 and all files in the cloud. We have a policy saying that all files and emails must be work related. At the start of last term, I asked everyone to come up with a password that they only use at school and to let me also know it. I keep this list securely in 1password on my phone with 2 factor authentication etc..

 

The reason I have asked for the passwords is mainly convenience for helping teachers/admin staff if they have any computer issues. It means that I can log in as them or unlock their computers if they're away so it doesn't hold us up or interrupt lessons while they're entering their passwords in to unlock the machine for me. I can also advise them on whether their password is sensible or not...

 

I have explained that office 365 allows onedrive access to global admins even without knowledge of a users password and that a mailbox could conceivably be access by changing it into a shared one but what do other people do? If people have documents they don't want me to have access to (which I have no particular interest in anyway) then they can be password protected.

 

Thanks,

Richard

Posted
Impero allows me to unlock machines if required. If I need to log on as them I change their password (and let them know I've done so) I would never maintain a list of user passwords.
  • Thanks 4
Posted (edited)

I wouldn't advise that on any level.

 

Passwords are encrypted and hidden even from administrators for good reason. Knowing anyone's password makes you vulnerable in the event of a data breach or allegation.

 

"I didn't put that file there!"

"But the audit trail says it was you"

"But it wasn't me. the NM knows my password!"

 

Yikes. You're in trouble.

 

It is an accepted level of responsibility for the role that as the Network Manager you have access to everything on the network. As you rightly say, if it's strictly confidential then a file can be password protected. Appropriate auditing policies cover when and how things were accessed, and by whom, which applies the level of protection if anyone accuses you of snooping around.

 

O365 has audit logs which can be set up and viewed as appropriate, too.

 

I'd reconsider this strategy at the earliest convenience.

 

ninja edit: and I agree with @LukeRowberry . Encouraging them to freely provide their password goes against all known methods and acceptable use policies. You have to also consider the possibility that users keep the same password for multiple things. Do you really want it on your head that you may be holding onto someone's banking password?

Edited by Mako
  • Thanks 2
Posted
Yes that would make sense. We're with Netsupport and I'm not sure the system allows me to do that. I'll contact them about it.
Posted
...but surely then if Impero can unlock a machine then I could still upload a file onto that machine and not appear in the audit trail as it coming from myself...?
Posted
I wouldn't advise that on any level.

 

Passwords are encrypted and hidden even from administrators for good reason. Knowing anyone's password makes you vulnerable in the event of a data breach or allegation.

 

"I didn't put that file there!"

"But the audit trail says it was you"

"But it wasn't me. the NM knows my password!"

 

Yikes. You're in trouble.

 

It is an accepted level of responsibility for the role that as the Network Manager you have access to everything on the network. As you rightly say, if it's strictly confidential then a file can be password protected. Appropriate auditing policies cover when and how things were accessed, and by whom, which applies the level of protection if anyone accuses you of snooping around.

 

O365 has audit logs which can be set up and viewed as appropriate, too.

 

I'd reconsider this strategy at the earliest convenience.

 

ninja edit: and I agree with @LukeRowberry . Encouraging them to freely provide their password goes against all known methods and acceptable use policies. You have to also consider the possibility that users keep the same password for multiple things. Do you really want it on your head that you may be holding onto someone's banking password?

 

 

...but I'd made it clear when it was created that it was only for their school account.

Posted
...but I'd made it clear when it was created that it was only for their school account.

 

That's placing too much trust in an end-user. It's human nature. As you can't verify whether or not they use that password elsewhere, it is safe to assume that at least one of your staff will be using that password for something else online. We have the same AUP's as everyone else that say to only use your work e-mail address for work business, but every so often I see someone has registered on Amazon or signed up to a CompareTheWhatever site and bought something for their house or obtained a quote using a work e-mail, because it's easier for it to be sent to the address they're currently logged into than go home and do it.

 

I tell staff to do and not to do a lot of things. Doesn't make it happen. This is a side-point though, the more glaring issues are what I outlined above.

Posted
...but I'd made it clear when it was created that it was only for their school account.

The fact you used impero to perform said task would be logged in impero.

 

 

Sharing passwords here results in a disciplinary. its bad practice and the second something goes wrong the user will deny it and then it is on your back.

  • Thanks 1
Posted
Does Impero actually unlock the session, or just log it off? I can't see how, without serious hacking of whatever msgina.dll is these days, it could possibly unlock you into their session without the password.
Posted

With Office365 you can (effectively) impersonate a user and access their OneDrive and their e-mails from your admin account. There should never be a reason that you access their actual account unless you're seizing it.

 

As for unlocking computers, why would you need to if everything is stored in the cloud?

Posted
I just can't see that this policy does anything other than reinforce bad habits on several levels. The excuse of 'it's more convenient this way' is usually a big red flag when it comes to security.
  • Thanks 1
Posted

To be blunt - that is a terrible policy. One of the core principles of computer security - don't share your password with anyone. Not the admin, not your family. No-one.

 

Convenience is not a reason to reduce security!

 

Here? If I need access to someone's session, I ask them to log in for me. If they aren't available, then the task waits until they are. If it is urgent, I reset their password and issue them with it when I'm done, so they can change it.

  • Thanks 3
Posted
With Office365 you can (effectively) impersonate a user and access their OneDrive and their e-mails from your admin account. There should never be a reason that you access their actual account unless you're seizing it.

 

As for unlocking computers, why would you need to if everything is stored in the cloud?

 

This sort of scenario:

A member of staff says to me "When I open Word and try to open "...." it comes up with a message "...". "It happens intermittently and I bet it won't do it when you're here. It's really interrupted my lessons and has happened with a few documents before etc etc."

 

I take all of your points on board, though, and despite having a lovely team of staff, it's worth being more careful.

Posted (edited)
This sort of scenario:

A member of staff says to me "When I open Word and try to open "...." it comes up with a message "...". "It happens intermittently and I bet it won't do it when you're here. It's really interrupted my lessons and has happened with a few documents before etc etc."

 

I appreciate what you're saying, I get it, and I've had staff before say "My password is X", but it boils down to needing to educate and enforce more rigorous error reporting. Screenshots for example. Windows' built in Problem Steps Recorder can be really good for it too.

 

I operate the same way @localzuk does. If I need to specifically be on their session, I ask them to login for me. If they're not around, it waits. I find most things can be fixed either at the PC level (so it effects all users and I test it with my test accounts) or remotely (it's a file issue, for example, and I can access their user areas via the file server)

 

Edit: Anyway, to answer your original request, as an admin you should have a way to access anything on your network/domain/etc, and then it's down to principle and policy saying you don't access it unless you need to. A member of staff still has a reasonable expectation that you won't go trawling through their files and/or emails just 'cause you're bored (not that I'm trying to insinuate that you do). So if a member of staff has something they don't want you accessing, fine, 'cause you're not accessing it anyway. You have better things to do.

 

They should be presented with this information and agree to it as part of an AUP.

Edited by Garacesh
Posted
This sort of scenario:

A member of staff says to me "When I open Word and try to open "...." it comes up with a message "...". "It happens intermittently and I bet it won't do it when you're here. It's really interrupted my lessons and has happened with a few documents before etc etc."

 

I take all of your points on board, though, and despite having a lovely team of staff, it's worth being more careful.

 

If we need access to their account without them being present we reset their password with their agreement or if it's (very rarely) going to be longer term we set an agreed password. Once the work is complete we get them to reset their password.

 

With the advent of the age of cloud identity management is critical to security and secure password management is at the core of that.

Posted

It's very rare that we need to ask staff for their password.

Impero lets us unlock the workstation is required (and that action is logged)

If we need to check something on 365 that they have raised an issue with, we can grant ourselves permissions via the console to login as their account (again all logged via the systems)

 

We used to hold details of students passwords to aid staff when student X forgot it, but we have long since even replaced that method.

 

The idea of the IT staff keeping a list of staff passwords is just mad imo.

Posted

I'd go further and make a positive point of not knowing users' passwords. Even when admins haven't asked for passwords to be handed over to them in escrow, a lot of people just assume that we can see their passwords in plaintext whenever we need/want to. When a member of staff starts to announce their password to me, I cut them off mid sentence and play up the whole hands-over-my-ears-going-blah-blah-blah thing. They need to know that passwords really are private, even from admins. You don't want users thinking that suspicious activity in their account is just an admin poking around doing techie maintenance stuff. You'd want them to see it for the suspicious activity that it is, and to feel free and able to change their password at any point.

 

One of the things in the 'annoying things' thread on here is teachers asking for help with something and then wondering off just when we need them to enter their password. Annoying, but an opportunity to educate them on the above.

Posted
OK and going forward what are people's policies on two factor authentication? I have it enabled on all of my accounts but do people insist this is set up for other school users?
Posted (edited)

We don't do any 2FA stuff here. I'd like to link staff Windows logons to access tokens, but we use RFID keyfobs rather than the typical swipe-card 2FA keyboards are usually built to utilise.

 

Staff and pupils can enable 2FA on their G Suite accounts if they want to, but it's not mandated.

Edited by Garacesh
Posted

I agree with everyone who is saying passwords should never be shared. The only exception to this would be any admin passwords which are in your Big Red Bus pack - i.e. the critical information needed should the IT Manager be hit by a big red bus, or other unexpected absence - and that should be held very securely anyway (ours is in a safe in the Headteacher's office).

 

As for the given scenario of an intermittent, user-specific issue - in my experience, those are almost invariably user errors (PICNIC error - problem in chair, not in computer), so me sitting down at the computer as that user and doing the task correctly probably won't generate the reported error anyway. Teach users how to take screen-shots. Especially for intermittent issues which might not occur when you do go and look anyway.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...