Jump to content

Recommended Posts

Posted

Hey guys, I'm a Network Manager at a fairly small special school in Durham, we only have about 65 machines. The head give me strict instructions last night to change all our administration passwords and change the IT teacher from an Adminstrator back to a normal staff user due to a few complains he has had against this particular teacher. When the head explained the situation to the teacher he has kicked up a massive fuss and send numerous letters to both the school governors and his union.

 

He also mentioned that if we were a main stream school we would require 2 administrators is this true?

so i was just wondering, Do the IT teachers in your school have admin rights? and also how many administrators do you have in your school?

 

 

Thanks

Ian

Posted

You should have 2 administrative accounts as a standard practice incase you are off ill, and it should be assigned to either the Head of IT or your next in line, whichever is appropriate in your case. I have 2 accounts, one of which is mine, the other is my bosses.

 

But in the grand scheme of things, I am the only one who does the administering!

Posted

IT Teachers are not part of the administration setup, they are teachers so there is no reason/need for them to have Admin rights.

They do not control the network, they teach the curriculum, so like any other teacher they should have a teacher account.

If you were not there then I would say fair enough, but as you are the network manager and responsible for the network you shouldn't grant them permissions on the basis that if he cocks things up, it's on you.

Posted

IT teachers have the same restricted rights as other teachers.

 

What you could do is have your 2 admin accounts but disable one which could be enabled by the HT in the case of your absence. All he needs is an mmc - right click - enable and possibly change the password. You then disable it on your return.

 

Just a thought :)

Posted

I've come to the conclusion there are some (a minority) of ICT teachers who are control freaks when it comes to permissions/access rights and they haven't a clue what they're doing but they want access anyway?

 

I usually take the approach and say you have one account for teaching (just like other teachers) and an admin account in the event a particular task requiring admin rights is needed. The majority have agreed with my justification and reasoning but a few ICT teachers unfortunately do not "get it".

Posted
I'm in a small school aswell and i have the only administrator account my ICT coordinator wanted admin access but i flat out refused as he has no need for admin access and would only mess things up. I have the account name and password written down in an envelope in the safe that is only to be oped in the event of my death
Posted

IT Teachers should NEVER be administrators (apart from in a very small school where the Network Manager and IT Teacher are the same person, very rare these days). If there are not two IT professionals in the school, have a second administrator account given to the Head in a sealed envelope for use in an emergency.

 

He can scream to his Union/Govs if he wants, but he'll get short shrift, and that's before you even get started on the Data Protection aspects of a classroom teacher having unbridled access to everything!

Posted
We have a couple of admins plus account details in the fireproof safe with other details and keys incase a freak accident takes teh whole IT Dept out & an external contractor needs to come in.
Posted
You do not need two accounts but you do need a note of the admin account in a fireproof safe.

 

Russ

 

If one account gets currupted how do you fix it? ;)

Posted

We have a total of 3 admin accounts - myself, my manager (bursar) and the normal domain admin account. The domain admin password is also kept in the fireproof safe.

 

No teachers, be they IT teacher or the head teacher have an admin account.

 

There are many reasons that they shouldn't have those privileges such as the Data Protection Act, the fact that the more people who have such accounts, the more likely a password falls into the hands of someone who shouldn't have it, the increased risk of serious damage to the network.

 

Also, by having those rights, there could come a time when the head or someone would turn to them and ask them to do something 'adminy' which they are not allowed to do under their contract. So it is in the teacher's best interest not to have it!

 

Best solution with this is to ask them to explain *why* they want such privileges.

Posted

@spiderz:

 

No other person should have admin rights but yourself, you should have 2 admin accounts in case one admin account for some reason cannot be accessed.

You as the network admin are responsible for the smooth running of the network and you should heed the request given to you from your Headteacher as he is legally responsible for the school.

If you feel the Headteacher is acting in an unreasonable way towards a fellow colleague then you have to go higher.

 

All written records are to be put into the school safe. :) :)

Posted
IT Teachers should NEVER be administrators (apart from in a very small school where the Network Manager and IT Teacher are the same person, very rare these days). If there are not two IT professionals in the school, have a second administrator account given to the Head in a sealed envelope for use in an emergency.

 

He can scream to his Union/Govs if he wants, but he'll get short shrift, and that's before you even get started on the Data Protection aspects of a classroom teacher having unbridled access to everything!

 

Remember that this is a very small school so it is likely that a non-IT person would need "second admin".

 

If the head has said that the second person shouldn't be this teacher then it stops there - the IT manager (whatever their title) should absolutely accept that instruction.

 

Just out of interest, what bit of the DPA says a teacher is less likely to be trustworthy in terms of access to data than a member of the IT Support Team?

Posted

I'm suprised at some of the replies here.

As far as I'm concerned there should be one main "domain administrator" account - ideally not called "administrator" by the way - such any easy thing to avoid and prevent 50% of a potential hackers job to be already done!

 

Once you have that one overall adinistrative account, it should only ever be used by the SINGLE person with overall top-level administrative control of the network - and even then, not as their main day to day account.

 

All other administrative users should have delegated access to required services (so if you have a technician needing to backups give them "backup operators" etc etc)

 

This fireproof safe idea is something I don't operate, but am 50/50 on. The only time it would ever need to be utilised is if the entire network admin team were blown off the face of the earth - in which case the server room they are based next to would have gone with them!

In some schools (especially smaller ones) I can see it being a good idea - as long as there was clear understanding it wasn't to be used without written authorisation from the actual administrator or the headteacher.

Posted

Hmm I'm sure the union will not help him much surely the workload agreement means that teaching staff are not allowed to perform IT administrative duties?

 

Ben

Posted

This fireproof safe idea is something I don't operate, but am 50/50 on. The only time it would ever need to be utilised is if the entire network admin team were blown off the face of the earth - in which case the server room they are based next to would have gone with them!

 

What if the server room has been specifically designed not to be next to the IT office which should always be the case so in the eventuality the IT team are incapacitated all is not lost.

Data centres are usually designed this way so half of the machine room exists across another part of the building and so too the trained workforce, any damage to that part of the building only takes out half the usability.

 

:) :) :)

Posted
What if the server room has been specifically designed not to be next to the IT office which should always be the case so in the eventuality the IT team are incapacitated all is not lost.

Data centres are usually designed this way so half of the machine room exists across another part of the building and so too the trained workforce, any damage to that part of the building only takes out half the usability.

 

:) :) :)

 

What I meant was, the only reason for needing a password in a fireproof safe is if the ENTIRE technical support team was irradecated - litterally no one left available to the school who could access the server without that scrap of paper. In which case, as I said, in the case of small schools it would be a good idea to follow the procedure.

 

In my situation, and other schools with two or more support people, the only way that a password on a scrap of paper would be appropriate is if the ENTIRE support team was to encounter some simultaneous catestrophic accident causing death to each of them - which unless the whole support team regulaly travel together, is highly unlikely.

 

Even with both of those paragraphs put together, I would STILL not ever write down the top-level domain administrator account! I would only write down an account capable of performing delegated top-level administrative tasks and was audited, which would allow a competent administrator to rebuild the network and perform admin tasks in a disaster!

Posted
Just out of interest, what bit of the DPA says a teacher is less likely to be trustworthy in terms of access to data than a member of the IT Support Team?

 

The bit where it says that access to information should be restricted purely to those who require access to it. Network admin requires access to everything to keep it running. An IT teacher does not.

 

This fireproof safe idea is something I don't operate, but am 50/50 on. The only time it would ever need to be utilised is if the entire network admin team were blown off the face of the earth - in which case the server room they are based next to would have gone with them!

In some schools (especially smaller ones) I can see it being a good idea - as long as there was clear understanding it wasn't to be used without written authorisation from the actual administrator or the headteacher.

 

As far as I'm aware, the fireproof safe thing is a LEA advised (or in some cases, required) thing.

Posted (edited)

I'm from a very small school - 40 machines including the server.

 

The ICT teacher has no admin rights and neither do I day-to-day. I have an admin account (password locked in safe) that I use when I need admin rights, but generally I can manage with standard staff rights (plus my admin account using remote desktop :) )

 

Due to the sensitivity of data that can be accessed with admin rights, there is absolutely no way that anybody should routinely be using such an account... and definitely not a teacher. If his permissions do not allow him to do his job - security options may need to be tweaked, but using admin rights as an easy fix is not the solution.

 

Might I add, it makes a pleasant change to have a HT that is aware of data security and is asking for the right thing. Too often we hear the opposite on here and SLT are not aware of the data security implications and demand privileges for themselves or others that they shouldn't have.

Edited by elsiegee40
Posted
Hey guys, I'm a Network Manager at a fairly small special school in Durham, we only have about 65 machines. The head give me strict instructions last night to change all our administration passwords and change the IT teacher from an Adminstrator back to a normal staff user due to a few complains he has had against this particular teacher. When the head explained the situation to the teacher he has kicked up a massive fuss and send numerous letters to both the school governors and his union.

 

He also mentioned that if we were a main stream school we would require 2 administrators is this true?

so i was just wondering, Do the IT teachers in your school have admin rights? and also how many administrators do you have in your school?

 

 

Thanks

Ian

 

We have several adminitrative accounts on our system.

 

The main Administrator account is never used, the password for it is ridiculously complex, and it is on a piece of paper inside a sealed envelope in the school safe, together with all the other service account passwords that may be needed in the event of an emergency when there were no other IT staff in the building and they had outside support in for whatever reason.

 

There are 3 of us here, and we all have an admin account each. It can't do absolutely everything, but it can do everything that is needed on a day to day basis. They are specially taylored so they can only reset the passwords of accounts below them in ranking, so there's no danger of one of us going mental and locking everyone else out of the system or something like that. These admin accounts are different to our normal day-to-day accounts and are used speicifically for administration tasks and logging onto servers with.

 

In my experience it is unusual for a teaching member of staff to have adminitrative privileges on a school network, there's a lot of issues surrounding this, data protection being just one of many that would need to be addressed.

 

The other major difference between a member of technical staff and a member of teaching staff is the teaching staff are much more likely to leave the machine logged on, or accidentally without realising it give away the password to a whole class of students by typing it into the user name box instead of the password box while being displayed on a projector (oh yes it has happened) incidents like that do need consideration when deciding on appropriate rights to give someone on a system.

 

Start with the minimum needed and add bits as necessary, not the other way round.

 

Mike.

  • Thanks 1
Posted

In my school I have the main admin passwords and so does the one technician. Nobody else does.

 

Teachers can change pupil passwords using the LEA supplied SMS interface which they can access. They cannot change teacher passwords.

 

I agree that teachers do not need the admin password - but in my case I am Network Manager so have them. I don't use it though and log in as my staff password in the majority of cases. When I'm working on the network side of things I do use the admin account.

 

Can anyone tell me the difference between the Doman Admin and an Enterprise Admin account? I am a Domain Admin, but the LEA are our Enterprise Admins. I assume they are higher so have more control.

 

As an interesting aside - what would you do if you wanted a lower technician to not have as much power as a Domain Admin? What would you set them up as? The ability to:

 

Edit printers/queues

Change passwords

Build machines

but not edit the AD or create GPOs

 

GJE

Posted

I have 3 admin accounts - one held by the local authority IT team (In case a bus gets in my way), and two of my own - One that I occasionally have to log into in front of people to get things done.

 

I also work in a small special school, although I have a almost 1:1 ratio of PC's and Laptops - 140 PC's, 150 kids.

 

The extra account of my own is purely just in case the main account is damaged or (more likely) a kid decides it would be a good idea to enter my password wrong 5 times and lock me out for 20 mins when I need to do something.

 

Plus there is a copy of it all in the Fireproof Safe.

Posted
The bit where it says that access to information should be restricted purely to those who require access to it. Network admin requires access to everything to keep it running. An IT teacher does not.

 

Playing devil's advocate a bit, but there are lots of situations where teachers will require access to pupil names, addresses etc and almost none where an IT person needs that access (they need to be able to backup data etc but there's no reason for them to have access to the information contained in those files)

 

I'm guessing this follows on from the thread elsewhere where someone asked about if IT staff should have access to the head teacher's home area.

 

Ultimately, it comes down to trust.

Posted

I have one admin account at each school - in one I am the only one who knows it as there is no IT co-ord and in the other it is me and the IT co-ord - yes, he is a teacher, but he is very trustworthy and would never attempt to do anything for example to AD or group policy. He does any user name changes or password stuff when I am not here - as a part-timer someone has to do things then - I would not allow other teachers the ability to change passwords etc as somehow they would muck that up too....

In that school I would NOT allow the head or deputy anywhere near my server/network as they could not be trusted: one knows a bit about IT and would mess it up, the other knows nothing and..would mess it up

Posted

Ahh an argument I've had with many an IT Teacher/Head of IT:)

Only myself and the NM have admin rights over the entire network, everyone else, including SMT have standard teacher accounts.

Usually the only reason they want admin rights is to change a load of settings on the computers in their room, easily remedied this by giving them a staff laptop with local admin rights.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...