4 ms·
It depends on who in IT. IT is big and broad and depending on the company you can have all sorts of folks -- even developers -- who never have an actual need t
by c0nsumer 4y ago
It depends on who in IT.
IT is big and broad and depending on the company you can have all sorts of folks -- even developers -- who never have an actual need to change admin-level stuff on their own machines. Not everyone in IT is doing systems-level stuff that needs admin rights.
Having as few people in a company with admin rights to their machine is very helpful for securing machines. Sure, some will need it, but limiting it to only those with an actual need, really reduces risk.
- isbvhodnvemrwvn 4y agoAnd there's proactive and reactive approach to it as well. With reactive, you elevate your rights when you feel the need to, and your actions are recorded and then maybe reviewed by someone. It's not much more annoying unless you need admin rights frequently (which should not be the case, really). With proactive, you need a ticket and only then, maybe, you get to use admin mode, or someone else is going to do things for you, maybe correctly.
- c0nsumer 4y agoYep, exactly. Reactive is really not that bad, and most software to manage it can also have a preapproved whitelist of actions that automatically get elevated. It definitely takes planning and management and monitoring, but it can be done, and it very much does help Enterprise-type management.