Jump to content

Recommended Posts

Posted

Scenario - 1 Network Manager, 1 Tecnician

 

SLT wanting Technician (via personalised admin account) not to have file access rights to any member of staff's home directory. This leaves only the Network Manger with the ability, when required, access these areas.

 

Opinions please.

 

Thanks

Posted
I cant see it as a major issue to be honest. I would just leave a copy of your password in a safe incase you get hit by a bus.
  • Thanks 1
Posted
It would be easy to set 'deny' to that user on backups and data, but you would also need to deny him/her administrator access to the fileserver. This is essentially how I'd do it with our Samba fileservers, I could give a tech full AD admin rights (notwithstanding the ability for him/her to change passwords) yet deny them access to backups and data.
Posted

Why does SLT not want the Technician to have access to this information. If the Technician needs to do a restore, how are they going to do so. The time will come when you get fed up of doing things you will grant them access.

 

So if a teacher comes to you and says, can you copy this file to my area, can you print this for me, its in ...., No I dont do it everyday but I do if a teacher says they have lost a file, I will seach their area first before going to the backup server.

Posted

"At the rate you lot accidentally delete files?"

 

"Haha, nope - I'm not doing all of those restores".

 

 

What's the underlying issue? If they don't trust the person, find out why.

Guest TheLibrarian
Posted

Strictly speaking that is going to be a pain to achieve. The tech has an admin account what's to stop said tech resetting permissions etc.

 

You could set denies and then set up auditing on the various areas that the tech should not see.

 

If you really want this sort of security the tech has to lose the full admin account and you will have to create a custom admin account and delegate control on OUs to allow the tech to do some level of useful work.

Posted
Strictly speaking that is going to be a pain to achieve. The tech has an admin account what's to stop said tech resetting permissions etc.

 

It's only a pain to do if it was set up inflexibly from the outset. It would take me about 15min to do this.

Guest TheLibrarian
Posted
It's only a pain to do if it was set up inflexibly from the outset. It would take me about 15min to do this.

 

Playing Devil's Advocate

And you'd be certain that in those 15 minutes you would not have missed a way for me to get access to things I shouldn't?

 

What about testing?

Posted
Playing Devil's Advocate

And you'd be certain that in those 15 minutes you would not have missed a way for me to get access to things I shouldn't?

 

What about testing?

Pretty certain. notwithstanding the ability for an admin to change a password. but I'm in the vast minority of edugeekers who use samba instead of windows.. There's a reason why large corporations use *nix - some of the things that are a pain in windows turn out to be quite trivial if you have more options. I do agree it would be more difficult with windows though.

Guest TheLibrarian
Posted
Pretty certain. notwithstanding the ability for an admin to change a password. but I'm in the vast minority of edugeekers who use samba instead of windows.. There's a reason why large corporations use *nix - some of the things that are a pain in windows turn out to be quite trivial if you have more options. I do agree it would be more difficult with windows though.

 

That's cheating! ;)

Posted

Working day to day, I use a standard staff account and don't have access to home drives either... It prevents accidental damage.

 

I only have access if I log in with a domain admin account... And I certainly don't need that all the time.

Posted
Conversely, I always use a domain admin account as invariably I need to get to something on the server or on a pc that is inaccessible to normal users
Posted
I use my domain account at my desk, but a slightly modified staff account everywhere else. The only extra that I have delegated to my Staff Account is the abilty to change passwords in my User Accounts OU.
Posted

I think the SLT should consider why they are requesting this. DPA? Even then there is a case for access to actually administrate the network.

 

If they can't trust staff, they need to assess recruitment procedures.

 

My 2p ;-)

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...