Re: Helpdesk as local admin



IMO, the worst practice is the "standard password on a local admin account". This is essentially unchangable on a large network; anyone who ever knew it stands a really good change of it still being valid on random laptop, sold-off hardware, etc. It's wrong for many reasons. Another bad solution is the "well-known and shared" domain admin password. It too has many bad properties, tending to leak, needing changed when staff changes, and producing untrackable changes.

It's not intuitive, but you are far better off giving each help desk tech an individual domain admin account - in addition to a personal user account. And encouraging/enforcing the use of "runas" to execute commands.

Advantages of a per-tech admin account: No shared password; no "plausible deniability"; simpler termination handling; cleaner logs. You do audit privilege use, right?

Over twenty-five years, I have become convinced that anything leading to shared and reused passwords is just plain wrong, and you must always find a solution that doesn't involve more than one person using the same password.

--
Henry Troup
htroup@xxxxxxx

On Sat Feb 3 8:58 , WALI sent:

Hi Guys..

So what's the defined best practise regarding HelpDesk personnel be
given/told local admin account names and passwords on users PC/Workstations
in order to undertake routine fault finding and applications installation?

Help Desk techies also regularly inserts new workstations into the domain
hence they need certain privileges to be able to make new workstations join
the domain. What could be the most secure way given the fact that Servers
are running Win 2k3 and client machines are a combination of WinXP and Win2k.





Relevant Pages

  • Re: questions on setting up a mail server
    ... standard method built in to the protocol) require Cyrus SASL. ... use your existing user passwords. ... passwords held in plain text - the sasldb. ... PLAIN is the preferred protocol according to the docs and RFCs - LOGIN is ...
    (freebsd-questions)
  • Re: WindowsXP plaintext passwords on LAN
    ... Searching for "plain text passwords" at www.microsoft.com returns this as the third item in the search results. ... > Please reply only to the newsgroup so all may benefit. ...
    (microsoft.public.windowsxp.security_admin)
  • Re: SMTP AUTH implementation question
    ... but I needed to have somebody verify it for me (because a lot of this ... (i.e. for storage, on disk, of the plaintext passwords) ... already implemented the PLAIN and LOGIN mechanisms, ... I do know that the downside of PLAIN and LOGIN is that with those, ...
    (sci.crypt)
  • RE: ipopd plain text passwords
    ... Just an update and again Thank you both Pim and John for your suggestions. ... when I install ipopd it doesn't include the LOGIN authentication module. ... Subject: ipopd plain text passwords ...
    (Debian-User)
  • Re: Windows Server 2003 and Lanman98 / Omni
    ... Windows to accept plain text passwords. ... Microsoft network Server: Digitally sign communications set to ...
    (comp.sys.acorn.networking)