Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Security-Basics
[Top] [All Lists]

Re: Re: Securing workstations from IT guys

Subject: Re: Re: Securing workstations from IT guys
Date: 27 Nov 2007 15:49:18 -0000
<snip>
#2 If IT does not know the local admin password, how can they do their job, 
patching & maintaining the PC. Realistically, there shouldn't be any HR related 
applications that absolutely require end users to use the Admin ID to do their 
job. And there is no other reason for user to know admin password.</snip>

Where I work we use images from our corporate parent. We install them over the 
network, leaving the "admin" account password as it was set by corporate, which 
allows them to push updates they have tested for conflicts. AFAIK only the 
people who make the images and the Landesk software know that password. The 
local techs have two accounts, a "normal" account and a "shortname" account 
with full admin privileges. Normally the tech will login with the normal 
account, but when there is a need to install software or do anything else 
requiring admin rights the shortname is used. The shortname accounts are 
monitored more closely than the normal accounts, and any tech abusing his 
position will be dealt with appropriately.

<Prev in Thread] Current Thread [Next in Thread>