Jump to content

Recommended Posts

Posted

Hi all,

 

I'm curious how many schools or MATs use an external MSP for IT services but still retain admin access to key areas?

 

In our case, teaching staff recently received new Intune managed laptops from our trust to align IT across the MAT using Office 365 (we were previously a Google school). While it's great to have updated devices, they are fully managed by the trust's external MSP.

 

As the Network Manager at the school, I have no control over these devices or the Office 365 tenant. This has already caused issues. When staff need support, I have no option but to direct them to the MSPs helpdesk, despite being employed to manage the school's IT.

 

I have raised the issue above with the Trust previously (lack of access) but was essentially told that the Trust has an SLA with the MSP, and that I can't simply make changes to live environments without an audit trail in place. I understand this to a certain degree, but I am not necessarily asking for global admin access. Just enough to carry out basic tasks. 

 

Just a small 'rant' I suppose, but was wondering if this is the norm for any other IT staff within education?

 

 

Posted

My previous school, the NM left and the business manager decided to buy in the LEA's IT offering to work along side me Senior tech and 2 junior techs. We actually pushed back hard about the LEA helpdesk having any sort of admin rights to our domain. That whole set up was a bit of a mess and I left after 2 months so not sure how its panning out but I do know the junior techs are still there.

  • Like 1
Posted

Worked on the other side of the fence. School with IT Staff had appropriate requested permissions (Aka don't ask dont get). Certain none IT Staff had basic permissions again requested. However we always took the line we manage their Tenancy we never owned it so if they switched MSP we created a new GA account provided to new supplier. 

Posted
1 minute ago, akidosaint said:

Worked on the other side of the fence. School with IT Staff had appropriate requested permissions (Aka don't ask dont get). Certain none IT Staff had basic permissions again requested. However we always took the line we manage their Tenancy we never owned it so if they switched MSP we created a new GA account provided to new supplier. 

Really interesting point - the MAT owns the tenant, and the MSP just manages it. I'll keep pushing, because, speaking to the MSP, they don't have an issue. In fact, it would be helpful for them, as I wouldn't need to ask for tickets to be looked at constantly.

Posted (edited)

I... think this is probably a wider discussion about your role with your school/trust than an "IT" problem. Being sensitive here, you can't do your job without the required access & that has implications on you.

 

I would be making waves upwards through your line management. Kick off. Talk to your union.

Edited by DrCheese
  • Like 2
Posted

Working at an MSP as a head of department we had a mix of edu customers with admin rights and those without. The relationship has to be really tight and as the MSP, we had to trust that the school staff know their stuff. It all came down to having defined processes and a shared responsibility document detailing what changes could be made and what the change management would be around this. If you where to pull that together and say this is how you propose it could work to the MSP and the school, that may be a way in, especially then with the value you add to the service to the school\students. Be mindful of all the work you action would be taking revenue away from the MSP, so it all depends on how the MSP is motivated as may want to protect this.

  • Like 1
Posted

Oh I meant to add as well @HyperTech you could request from the MSP/MAT Intune Admin role or Entra Joined Local Admin role which would allow you to fix most end user issues rather than needing the GA role which might help in the short term

  • Like 1
Posted
17 minutes ago, buzzard said:

Working at an MSP as a head of department we had a mix of edu customers with admin rights and those without. The relationship has to be really tight and as the MSP, we had to trust that the school staff know their stuff. It all came down to having defined processes and a shared responsibility document detailing what changes could be made and what the change management would be around this. If you where to pull that together and say this is how you propose it could work to the MSP and the school, that may be a way in, especially then with the value you add to the service to the school\students. Be mindful of all the work you action would be taking revenue away from the MSP, so it all depends on how the MSP is motivated as may want to protect this.

Thanks for this, its very useful information. I do know of a couple of Trusts that have similar setups, e.g. their MSP will handle all 1st line queries/issues and then the NM will deal with more of the technical stuff - or vice versa. I will try and write up a document detailing the use case of needing such credentials like you mentioned. The schools/MAT have a very good relationship with the MSP and have been using them for years, my school has only recently joined in the MAT though, which might make a difference.

Posted

It's a difficult one.  For the MSP they want to give out as little admin access as possible to satisfy cyber security etc.

 

From your point of view you need as much access as possible so you can do your job!  Otherwise you basically end up being a first line support phone answerer which is not good for us get involved types (which most of us on here are).

 

Sadly this is getting more and more common.  I can see the "IT Manager" role ceasing to exist in many schools over the next 10 years.

Posted

Once I had the council IT people install a domain, didn't give me the passwords, but also their passwords were 7 letter all lower case, so 30 mins after they left I had them

Posted
53 minutes ago, mavhc said:

Once I had the council IT people install a domain, didn't give me the passwords, but also their passwords were 7 letter all lower case, so 30 mins after they left I had them

And the same for every other school they setup no doubt

  • Like 1
Posted
1 hour ago, dmj said:

And the same for every other school they setup no doubt

Of course. Another time I found the router password, because they used the same password for the difficult cisco encryption as the easy to crack cisco encryption, that was set up by BT I guess, so blame them, the Virgin one was done properly. Anyway, I basically had the passwords to the networks of all schools, council buildings, libraries, prisons..., and so did anyone else who'd had physical access to their routers an ever even tried to find them

Posted
16 hours ago, HyperTech said:

I understand this to a certain degree, but I am not necessarily asking for global admin access. Just enough to carry out basic tasks. 

 

As a manager, should you be doing this anyway? Wouldn't this be the responsibility of the level 1 technicians. As a manager, wouldn't you be more strategic and not be doing the day to day stuff?

  • Haha 1
Posted (edited)
44 minutes ago, FN-GM said:

 

As a manager, should you be doing this anyway? Wouldn't this be the responsibility of the level 1 technicians. As a manager, wouldn't you be more strategic and not be doing the day to day stuff?


 

I see what you mean, but I am the sole IT employee in our school. So I don’t have the ability to pass it onto anyone else. 
 

I wear all the hats so to speak, so if any sort of IT issue arises - it will be me that looks at it. Just frustrating when a password reset could take up to an hour, or I could do it in a couple of minutes. 

Edited by HyperTech
Posted
46 minutes ago, FN-GM said:

 

As a manager, should you be doing this anyway? Wouldn't this be the responsibility of the level 1 technicians. As a manager, wouldn't you be more strategic and not be doing the day to day stuff?

 

There are not many "hands off" IT managers in schools.  Might be different in colleges/universities.

  • Like 2
Posted

In relation to the OP. A common way to set this up is to use a form of "privileged access management" (PAM, but not to be confused with pluggable authentication module!!).

 

We have this setup where NOBODY has direct write access to production systems. (there are some failsafe accounts for very bad situations). 

All elevated permissions need to go through PAM, either a command line tool or a GUI. 

Certain users automatically get their privileges escalated for a set time whereas others need an approval for it and all requests are quite heavily logged. 

This is quite common outside education. Most changes happen as part of the CD pipelines anyway so it doesn't cause any additional difficulties. 

  • Like 2
Posted

Honestly I would just tell the school management that supporting these devices is out of your hands and that any staff member who needs support with them will thus need to contact the MSP helpdesk and not you. And don't offer to be the middleman (e.g. file tickets on their behalf) as this will just cause issues. They will then have to wait for the MSP helpdesk and if their response isn't what the user wanted - again they will have to take it up with the MSP.

  • Like 2
Posted (edited)
23 hours ago, HyperTech said:

Just frustrating when a password reset could take up to an hour, or I could do it in a couple of minutes. 

 

Not the entirety of your OP  I know, but could you get most applications setup with self service password reset systems?

Edited by Koldov
  • Like 1
Posted
19 minutes ago, mikes said:

Honestly I would just tell the school management that supporting these devices is out of your hands and that any staff member who needs support with them will thus need to contact the MSP helpdesk and not you. And don't offer to be the middleman (e.g. file tickets on their behalf) as this will just cause issues. They will then have to wait for the MSP helpdesk and if their response isn't what the user wanted - again they will have to take it up with the MSP.

Sounds like a good way to get a nice redundancy package

Posted (edited)
5 hours ago, dmj said:

Sounds like a good way to get a nice redundancy package

As I was trying to get across a bit more subtly earlier, this is the situation OP is currently already in. Needs to start raising, quickly, this as a concern with management & discuss with the union. Use management as a way to get the access that's needed (Don't go all "I'm not supporting that", instead "I need these tools to support you")

 

If you can't get access to do your job, then you risk being made redundant by the backdoor. 

 

Edited by DrCheese
Posted

Just two of us here, one IT Manager and me, the technician.

 

We used to have an MSP handling most things and the technician handled day-to-day repairs & password resets, but as the school grew and we now have 2 IT staff on-site, we went to a lower plan with them, initially just visiting once a month by the time I joined, then later we went to their lowest plan that is 20 hours a year, remote support only, and we use them as a 2nd-line support for issues we can't resolve with our own knowledge, or for things we don't do frequently to avoid risks of messing things up given we only have one physical server, no test environment.

 

 

  • Like 2
  • 6 months later...
Posted

Late to the party, but as someone who works day-to-day as a vIT Manager for a MAT and is also a senior member of an IT MSP, I can hopefully offer a balanced perspective.

 

Not all MSPs are the same.  Many of us are genuinely people-centric and focused on what works best for each school.  While we specialise in outsourced IT, we’re equally comfortable working alongside in-house teams where that’s the right fit — because no two schools are the same.

 

Where we commission and support services, we’d normally expect to support them end-to-end.  That said, where there’s trust and a clear need, overly restricting admin access can create bottlenecks and make user support harder than it needs to be.  In schools with capable in-house IT, appropriate access usually improves efficiency and collaboration rather than causing issues.

 

Ultimately, it’s about balance and relationships.  Problems tend to arise only when changes are made without communication, which is thankfully the exception.  A good MSP should be open to sensible conversations about access, not operate on a one-size-fits-all model.

  • Like 2
Posted

I had to check for an audit only last week. No one has admin update access internally. 2 or 3 people have read only access. Including my LM's LM, formerly my LM. He wouldn't know what to do with it but I guess it adds to a feeling of importance. I've had a couple of reasons to run a read only PS script or MS Graph script because first line support don't have the skills to to run one. Only in the last couple of days a query came up about getting everyone's MS Outlook calendar updated with bank holidays. I suggested asking support to do that. They basically said they can't easily. 5 minutes on ChatGPT gives 3 solutions including providing PS scripts or MS Graph solutions. The irony is the MSP is running an AI training session in 2 days time :rolleyes:

Posted (edited)
16 hours ago, pipsyp said:

Late to the party, but as someone who works day-to-day as a vIT Manager for a MAT and is also a senior member of an IT MSP, I can hopefully offer a balanced perspective.

 

Not all MSPs are the same.  Many of us are genuinely people-centric and focused on what works best for each school.  While we specialise in outsourced IT, we’re equally comfortable working alongside in-house teams where that’s the right fit — because no two schools are the same.

 

Where we commission and support services, we’d normally expect to support them end-to-end.  That said, where there’s trust and a clear need, overly restricting admin access can create bottlenecks and make user support harder than it needs to be.  In schools with capable in-house IT, appropriate access usually improves efficiency and collaboration rather than causing issues.

 

Ultimately, it’s about balance and relationships.  Problems tend to arise only when changes are made without communication, which is thankfully the exception.  A good MSP should be open to sensible conversations about access, not operate on a one-size-fits-all model.

Completely agree. To be honest, the issue in question comes more from the MAT. I suppose they don't want to open themselves up to potential issues when they already have an SLA in place. The MSP would be open to it, as I know they support other schools/MATs and collaborate with the in-house teams on a closer level. But ultimately, it isn't their decision to make. As others have said, when you are a "Doer" it is frustrating having to wait hours for a print driver to be installed.

 

I suppose, as you mentioned - it just creates a unnecessary "barrier" to workflow. I think the school finds it especially hard, as they have had an in house technician for nearly 15+ years.

Edited by HyperTech
  • Like 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...