3 ms·
Give everybody in the company local admin rights. This will give all staff the ability to experiment and learn more about technology. Since everyone now has l
by hackbinary 10y ago
Give everybody in the company local admin rights. This will give all staff the ability to experiment and learn more about technology. Since everyone now has local admin and they can now manage their own computers, you can fire the IT staff who previously managed these workstations.
- 1ris 10y agoThis sounds like it will result in a better environment that there is in many places. I have seen places with a strict "don't install anything policies" far to often. (I have even seen terms that techincally forbade executables in the home dir. For programmers.) Don't use anything you like. Or want. Or could use to work more productive. Use the outdated debian version of the shitty software that the benevolent admin choose for you. And good forbid you BYOD. Or want to the admin to install anything else. Fist of all, the admin knows best, second it's not in the debian repos. Given you have backups and ensure they can't fiddle with the authentication system: Go for it. It's like BYOD but with provided hardware.
- hackbinary 10y agoWe give our people who have reasonable need Local Admin. Giving local admin to the non-technical staff who want to download 'free' software (not FLOSS, free as in beer) because they think (at best) that they are saving the company money, but instead infest their computer malware. Most people are totally disinterested in their computing environment, let alone managing it. We standardise on certain packages because there is utility in having common programs from support, training, and administration points of view, but ultimately if there is a good reason to get/use something else, we will do that. Furthermore, any user with a local admin access can use a Kerberos 'Golden Ticket' leverage attack to gain full domain access across the entire realm. Are you seriously telling me that you want the teller at your bank to have local admin access to his workstation? How about the person at the IRS/CRA/HMRC/<you government tax office> that you just called? Local admin has its place, and certainly the first test is that will the person endanger their system by running dubious programs. The next question is if that person does infect their system, can they clean up the mess themselves? We went from a situation where we had local admin across our estate where we had at least one virus problem a week to one where I can not remember the last time we had one. Finally, can you really trust a Windows workstation after it has had an infection?
- prdonahue 10y agoYou must work in IT?
- hackbinary 10y agoYes.
- maxxxxx 10y agoFor me having admin rights is the only way to get things done.
- hackbinary 10y agoAnd you are a technical user who probably is responsible and thoughtful about what you do on your computer. Most people are not.