Jump to content

Recommended Posts

Posted
We also give access to some teachers who require it to go into student areas, and also some IT teachers have the abilty to change password. You can delegate all these permissions with AD and NTFS permissions. I reckon the teacher does not know what the domain account really involves so calm them down and give them the level they want. No one should be logging into a computer with domain admin, I know I do which is bad practice but thats not the point.

Yes, so do I and I know I shouldnt. I agree though give them what they want, locked down as far as you are able.

 

I sometimes answer my pre-loaded questions myself ... it comes from constantly having conversations with myself and forgetting who should be answering who. :)

 

Now that IS disppointing, Grumbledook - 'who should be answering whom' is correct :)

Posted

My line in the sand is read-only access to student my docs, no access to other adult my docs, no one ever gets their normal user account made an admin. I've been expecting but have yet to encounter a compelling request for write access re. SEN kids etc. Password changing doesn't bother me provided it is limited to a select few because it leaves tracks you can refer back to if necessary... not bothered includes the prospect of say one SLT being in a position to change a teacher's password.

 

Standard defences: "This runs against the grain of [magic word with emphasis] E-safety blah-blah.." and one of those true stories of the very serious inconvenience when a promoted-to-admin teacher account got hit by some brand new and thus undetected malware, which swiftly got the entire domain.

 

The trust issue is fun, in the sense that some folk just don't appear to have ever considered how much access you have until you talk about it re. the seriousness of giving it to someone else. I always used to think trust/ethics was part of what you got paid for in the private sector, so next time you're sulking over the pay-slip perhaps that ignorance is part of the problem... ;)

Posted

and the Admin passwords need to be lock in the school safe. Just in case you run over by a bus.

There's the answer. Things with the admin password need to go in the safe. Give the teacher the password then put them in the safe :D

Posted

For reference our Head of ICT only has teacher level access.

 

Having said that a better line of discussion is "What exaclty are you trying to achieve?" As them to list the things that they need to be able to do and you will see if you can do it without giving them domain admin rights. i.e. through NTFS permissions and delegeated control as has been mentioned.

 

I'd also point out that with domain admin rights they could go through everything if they wanted to. Even if you blocked their access they could take control and change the permissions.

  • 4 weeks later...
Posted

at our school, when i started all the "admin" staff (i mean the lovely ladies in the office) were domain admins, along with all of the it teachers and a few other random teachers.

 

the admin staff were because apparently "that is the only way sims and fms will work" :rolleyes:

 

the it teachers were because they were it teachers.

 

which was great because all staff were sharing a redirected start menu, and the it teachers quite often decided to uninstall software from computers, removing the shortcuts from everyones start menu.

 

conficker infections were rife as all these domain admin accounts automatically had access to the C$ and admin$ shares on all the machines and could create schedulded tasks.

 

new folders would randomly appear and existing ones disapear from the shared area.

 

loads of other problems, I go on,

Posted
at our school, when i started all the "admin" staff (i mean the lovely ladies in the office) were domain admins, along with all of the it teachers and a few other random teachers.

 

the admin staff were because apparently "that is the only way sims and fms will work" :rolleyes:

 

the it teachers were because they were it teachers.

 

which was great because all staff were sharing a redirected start menu, and the it teachers quite often decided to uninstall software from computers, removing the shortcuts from everyones start menu.

 

conficker infections were rife as all these domain admin accounts automatically had access to the C$ and admin$ shares on all the machines and could create schedulded tasks.

 

new folders would randomly appear and existing ones disapear from the shared area.

 

loads of other problems, I go on,

 

Quod erat demonstrandum.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...