Jump to content

Recommended Posts

Posted

Hi All

To summarise from the beginning, our new Head feels that NO teaching staff should have access rights to other staff member user folders. Now thats fine - we've been setting permissions since day 0

 

However, as our Head of ICT has domain admin rights this obviously "gets around" the permissions. All with good reason really, as he deals with support issues regularly, both from staff and students

 

Its one of those situations where I feel he should have access rights, as otherwise my workload goes through the roof (again), but on the other hand i'm tempted to say, "lets go along with it" and see what uproar it causes

 

What do other schools do? Are your Heads of IT / ICT merely "users" or do they have higher privileges?

Posted

Our head of ICT "stole" admin rights really, but rarely uses them. The most he has done (and it could have been bad I suppose) was to re-enable a disabled account (staff account) to get at some work inside the folder. I would prefer to have the Head of ICT as a normal user. Simple. But in schools politics usually reign and in this case I have to go with the flow.

 

It depends on your Head of ICT really. How much do they really know about ICT (not Office and VBA, real IT)- and if they can handle the responsibility. Difficult one though.

Posted
Hi All

To summarise from the beginning, our new Head feels that NO teaching staff should have access rights to other staff member user folders. Now thats fine - we've been setting permissions since day 0

 

However, as our Head of ICT has domain admin rights this obviously "gets around" the permissions. All with good reason really, as he deals with support issues regularly, both from staff and students

 

Its one of those situations where I feel he should have access rights, as otherwise my workload goes through the roof (again), but on the other hand i'm tempted to say, "lets go along with it" and see what uproar it causes

 

What do other schools do? Are your Heads of IT / ICT merely "users" or do they have higher privileges?

 

kingswood ( aka my network manager LOL ) above gave a good reply but just wanted to add a couple of things.

 

To summarise from the beginning, our new Head feels that NO teaching staff should have access rights to other staff member user folders

 

Considering the head of ICT is a member of staff, does that include him / her when they say that and I can understand that as well from a data protection act point of view as well to a certain degree obviously.

 

All with good reason really, as he deals with support issues regularly, both from staff and students

 

What sort of "support issues" are you reffering to here ?

Posted

The Head of ICT is simply another head of department. Purely because they use the IT equipment more than other HoD's does not mean that they should have more access rights than the others.

 

Giving someone without the correct knowledge the wrong level of access could bring about disaster as whats to stop them from telling someone else then them someone else, etc.

 

At my place there are two people who know the admin password, me and the ICT Tech. I have also placed a sealed document in the schools safe documenting the relevant passwords which it only to be opened by my replacement. This was at the heads request.

Posted

I gave our head of IT the same rights as staff, and i would like to take that away from him. He keeps going home and leaving him self logged on all over the place, not even locking the workstation, and kids are in the room.

 

Staff can get into kids documents, reset there passwords, add printer credits, turn the walled garden on and off, it scares me how complacent he is over security.

Posted

The nyou should raise that fact to his line manager as it must surely be a breach of the AUP?

 

Our head of ict has the same access rights as any other member of staff and will get domain admin over my cold dead body.

 

Ben

Posted

Head of ICT has some additional access on the interweb ... but is a staff account for everything else.

 

She doesn't want anything more either ... a) she doesn't get paid for it and the union would play merry hell if she was asked to do "support" or "admin" stuff; b) she doesn't know her way around AD and knows she would have to spend a few months trying to get to grios when she doesn't need to; c) all staff have to sign the same AUP as students ... I treat everyone equally ... they are all lower forms of life compared to sysadmins!!!

Posted

I agree, Head of ICT is simply a teacher so why they should they have elevated rights? Just asking for trouble.

 

I give staff normal user permissions plus access to read pupils' home folders and change pupils' passwords. They cannot change staff passwords, view staff work, enable disabled accounts or unlock locked-out accounts.

Posted
Surely best security practise would be that NO 'normal' user account should have Admin rights. If a particular member of staff is permitted to perform Admin functions, then they should have an additional user account which has the necessary rights, and they should use that account only when they have to. The Administrator user account should either be disabled, or a very strong password set and stored in a sealed envelope in a secure location (eg school safe).
Posted

Same with me IT head only has same rights as any member of Staff.

 

@Grumbledook, LOL we know we are a much more advanced set of life forms than everyone else but thanks for confirming that again :)

Posted

'Over my dead body' lol - that's how I feel about it as well. Presented on a teachers' forum or discussed with teachers, this is a very thorny topic. As such this conversation has to be viewed from a techs standpoint.

 

We're not about enforcing our way on the poor unsuspecting teacher, but as eloquently discussed above, there are serious points as to why this is so.

Posted
@mark: As you say, some teachers feel positively violated when told that they cannot have admin rights. I think that this boils down to the fact that they feel less important if they think they are missing out on something like this.
Posted
Lol yeah, this has been covered on the TES forum (where most teachers look down their noses at support staff) and teachers always believe they have a right to admin privileges.
Posted

Taking the middle line here ... some schools have had staff having various methods (including admin priveleges) to get to students' work and even to the home areas of other staff (to get resources) because that is how it has always been set up from the old days of peer to peer networking.

 

If you take away the admin rights of the teachers you have to a) provide them with an alternative solution that will still allow them to work, b) retrain them in better methods of sharing resources ("hey folks ... I've an idea. How about a shared drive on the network that only staff can see and share resources on!?") c) they are often not aware of the legal background (DPA etc) that we have to strive to and it may actually help them understand if we explain it a little ...

 

It is a bit like licensing. I point out to people that as part of my job it is *my* responsibility to ensure licensing is correct in the school. Not the Head, not the Chair of Governors or aanyone else ... me ... and that means that should FAST or particular companies come banging on the door I am the one that has to answer to them ... and I am the one who gets the £30,000 fine!!!! So it is in my interest to make sure it is correct ... and if I find anyone who intentionally deceives me then they are going to get dragged up on a disciplinary and I will be speaking to a lawyer!!!!

 

Ok ... the DPA and computer misuse act are usually enough to make them realise we are just following rules and actually trying to protect them from students (or even other staff) saying "But all my work has gone ... someone has it in for me!!!"

Posted

@Grumbledook: I totally agree that means should be put in place to allow staff to work effectively. If admin rights are required to do X, there is probably a way to do it by changing permissions, etc.

 

One of the things that I found not too long ago was staff wanted to be able to trial apps and stuff. Obviously, installing apps requires admin priviledges which I don't give them. I found a solution to the problem using virtual machines. I then explained that the purpose of these was for testing and that it was their responsibility to back up anything they do. I also explained that they are responsible for ensuring any software used is licensed. The AUP backs this up.

Posted

At our site we have different levels of access

 

Pupils... only see 2 drives their Home and a Sheared Read only folder that staff put stuff into

 

Staff.. Only see a few more folders .. Hvave access to printers and read of Student folder

 

ICT staff.. Password Change, Read and Write of Student folders and a few more things

 

Tech Staff.. are the only ones to have Domain Admin rights..

Posted
Our head of ict has the same access rights as any other member of staff and will get domain admin over my cold dead body.

 

Ben

 

You are me. :)

 

"I don't teach the kids and you don't admin the network"

Posted

One of the things that I found not too long ago was staff wanted to be able to trial apps and stuff.

 

I gave them a standalone PC in the staff room that gets wiped once a month. Not that they ever used it...

Posted

Wow - didnt expect so many answers!

 

Its a difficult one as the Head of ICT was obviously managing the network long before I arrived and therefore knows what he is doing.

 

Its interesting but it appears from the posts that ICT Tech staff have domain admin rights; our Head of ICT obviously doesnt need these rights, but he is still considered by most staff to be part of support. Indeed he is probably more trusted than the ICT support team put together !!

Posted

I have the ICT coordinator as a standard user but she has my username and password for emergencies. I trust her not to mess around. At my old school I dreaded the thought of the ICT coordinator with that kind of access.

 

For me it all comes down to the quality of the ICT coordinator/head. But if Head of ICT was managing the network long before you arrived he must no some backdoors in and it would be unfair to kick him out.

 

Assuming he knows his stuff I would give his standard account user access but let him know the main admin account or give him a 2nd account with admin rights on the understanding its not for eveyday use. Hopefully he only logs in with his standard account and only use’s the admin access account when really needed.

Posted
Its interesting but it appears from the posts that ICT Tech staff have domain admin rights; our Head of ICT obviously doesnt need these rights, but he is still considered by most staff to be part of support. Indeed he is probably more trusted than the ICT support team put together !!

 

Really, you need to re-train the staff into thinking of the head of IT as a teacher. Under TLR, he shouldn't really be doing any tech support anyway and I'm sure he'd much rather spend his free periods preparing lessons and marking work without the constant influx of people wanting their passwords changed and the like.

 

By delegating tasks you can reduce your admin workload - the obvious one is password changing... a quick MMC and delegated access to staff is all that is required and it means that staff members can quickly change a password without sending the pupils half way across the school - mean less time wasted by pupils and aiding classroom management.

 

As for trust, that's a hard thing to gain. If the head of IT suddenly stops doing admin stuff you will probably find people being nicer to you and more staff will seek you out. In time, you will gain their trust ;)

Posted

We have pupil acces and Staff Access, both are heavily restricted, the only exceptions there are is that the Head of IT can Change passwords only and has access to the Kids User Areas.

 

If anyone can linky for me to the section on Data Protection that is violated by allowing staff access to the kids User Areas I would be interested.

Posted
Personal data shall be obtained only for one or more specified and lawful purposes, and shall not be further processed in any manner incompatible with that purpose or those purposes.

 

Appropriate technical and organisational measures shall be taken against unauthorised or unlawful processing of personal data and against accidental loss or destruction of, or damage to, personal data.
Posted
I have the ICT coordinator as a standard user but she has my username and password for emergencies. I trust her not to mess around. At my old school I dreaded the thought of the ICT coordinator with that kind of access.

 

One can debate whether or not ICT Teachers need elevated privilidges but you should never ever give your logon to anyone else. The only fall back the school should be able to insist on is to have admin credentials in a sealed envelope in the safe. Having your passwords means that they can read your email etc.

 

In this case if you have confidence in your colleagues technical abilities then you should create another account with limited admin caperbilites (password changing, print quotas, student folder browse etc.) which they can use.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...