Jump to content

Recommended Posts

Posted

An admin staff member has asked if I can install TeamViewer on her work desktop as it's ofen used by 3rd party companies the school uses for remote support.

I'm reluctant as I feel it's opening a vulnerabilty to our systems.

 

The alternative is she uses Teams and does a screen share, which I feel is at least a controlled method.

 

Thoughts?

Posted

If a third party is using this for support then they should have a small exe that doesn't install and you have to provide the generated code for the agent to be able to connect. Once the session is killed then they cant reconnect without rerunning the exe and providing the new code. That would be the correct way to do it. Its been a while since I used TeamViewer but it is possible for you to have an install and set it so that any incoming connection requests prompt for permission. 

Posted

Agreed.  It needs an IT team password to enable it to run here so that there is a second person verifying it is a valid request.

  • Like 1
Posted (edited)

I wouldn't allow this to be installed, as it can be setup to allow unattended access.

 

We do allow TeamviewQS (Quick support) to be ran when needed, but this needs admin rights so users have to contact us first before it works. (& Applocker stops users running .exe's we don't know about)

 

 

Edited by DrCheese
  • Like 1
Posted (edited)

Windows 11 Quick Assist is also a good inbuilt option (Microsoft Store App as well) which i use from time to time as can do the basic like request control etc.  Nice and quick for basic support.  Do need to be logged in with School account though.

Edited by JazzFlute
Posted

Our approach to TeamViewer was quite similar; we simply toggled the application control in our firewall to allow external support for the finance team as needed, and then switched it off again once they were finished. They (the 3rd party) had to connect us via email for pre approval and we confirmed this with the staff member that needed support. 

Posted

It's a major risk, but you can control it. We have multiple vendors supplying third party support who use a remote access platform to access machines on our network. It's not unreasonable for a tech company to have a system of tools to do their job. 

 

However, you do not need to leave it there as a backdoor for someone to access whenever they want. I have seen users allow that and support companies install it while they've got access to the machine. 

 

The executable mentioned above that doesn't install is plenty. 

 

Attackers pretending to be IT support is one of the most successful ways of getting remote access to a managed network. You need a process to ensure the person accessing machines on your network has a legitimate reason and is who they say they are. 

  • Like 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...