Jaan Posted October 19, 2022 Posted October 19, 2022 We have a team of 3 experienced IT Support staff members in our team. We don't really have a 1st line role at the moment, our most "junior" Tech Member is experienced enough to do duties that 2nd line or in some cases the NM would perform. You know just incase one of the team members get "hit by a bus", we have some contingency. That being said, our junior member will be leaving us soon and of course be replaced. What AD permissions do you give your 1st Line access to? Cheers
5tu Posted October 19, 2022 Posted October 19, 2022 Our first line tech just has delegated permissions for password resets (within selected OUs) group member changes (within selected OUs) and permissions to view Bitlocker Recovery Keys.
Jaan Posted October 19, 2022 Author Posted October 19, 2022 Our first line tech just has delegated permissions for password resets (within selected OUs) group member changes (within selected OUs) and permissions to view Bitlocker Recovery Keys. So just a domain user in AD?
5tu Posted October 19, 2022 Posted October 19, 2022 The delegated permissions are assigned to a group (say IT HELPDESK 1ST LINE) and then tech's privileged accounts (not their daily driver accounts) are added to this group. IT team members launch tools like dsa.msc using their privileged creds. All privileged accounts are still domain users in AD (not domain admins), but membership of permissions groups determine the level of delegated permissions assigned. Hope that makes sense!
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now