kennysarmy Posted May 14 Posted May 14 An admin staff member has asked if I can install TeamViewer on her work desktop as it's ofen used by 3rd party companies the school uses for remote support. I'm reluctant as I feel it's opening a vulnerabilty to our systems. The alternative is she uses Teams and does a screen share, which I feel is at least a controlled method. Thoughts?
NegativeKillDeath Posted May 14 Posted May 14 If a third party is using this for support then they should have a small exe that doesn't install and you have to provide the generated code for the agent to be able to connect. Once the session is killed then they cant reconnect without rerunning the exe and providing the new code. That would be the correct way to do it. Its been a while since I used TeamViewer but it is possible for you to have an install and set it so that any incoming connection requests prompt for permission.
sigma Posted May 14 Posted May 14 Agreed. It needs an IT team password to enable it to run here so that there is a second person verifying it is a valid request. 1
DrCheese Posted May 14 Posted May 14 (edited) I wouldn't allow this to be installed, as it can be setup to allow unattended access. We do allow TeamviewQS (Quick support) to be ran when needed, but this needs admin rights so users have to contact us first before it works. (& Applocker stops users running .exe's we don't know about) Edited May 14 by DrCheese 1
JazzFlute Posted May 14 Posted May 14 (edited) Windows 11 Quick Assist is also a good inbuilt option (Microsoft Store App as well) which i use from time to time as can do the basic like request control etc. Nice and quick for basic support. Do need to be logged in with School account though. Edited May 14 by JazzFlute
msi_school Posted May 14 Posted May 14 We use TeamviewerQS in the same way as @DrCheese is not an onerous process and keeps the computer secure.
Jaan Posted May 14 Posted May 14 Our approach to TeamViewer was quite similar; we simply toggled the application control in our firewall to allow external support for the finance team as needed, and then switched it off again once they were finished. They (the 3rd party) had to connect us via email for pre approval and we confirmed this with the staff member that needed support.
jmak Posted May 14 Posted May 14 It's a major risk, but you can control it. We have multiple vendors supplying third party support who use a remote access platform to access machines on our network. It's not unreasonable for a tech company to have a system of tools to do their job. However, you do not need to leave it there as a backdoor for someone to access whenever they want. I have seen users allow that and support companies install it while they've got access to the machine. The executable mentioned above that doesn't install is plenty. Attackers pretending to be IT support is one of the most successful ways of getting remote access to a managed network. You need a process to ensure the person accessing machines on your network has a legitimate reason and is who they say they are. 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now