John, Sorry to reply to this via the list, but I cannot see an e-mail address to contact you directly.
I have a similar situation with several surgery centers that we are responsible for. We do the day-to-day maintenance of the centers and have to work with a surgical software company that demands administrative access (albeit not by way of terminal services, but by way of PCAnywhere) to the servers to make regular updates to their software. Shortly after we took over the accounts from the person who was doing the work in-house, we made it a policy to completely block them from access to any directory except those directories to which they absolutely had to have access. We also implemented a policy of assigning every user from within the company who might have access a separate username and password and change the passwords on a regular basis. All access is logged and we are now in a much better situation to monitor the activity of anyone making changes to the servers. It's a bit of a pain in the butt to set up initially and we ran into some opposition from the client, but we made it very clear that, if we are to be held responsible and accountable for the operation and maintenance of their servers, desktops, and networks, then we had to have total security in place. Unfortunately, the contract signed by the client gives the vendor access to the servers at the admin level and they are refusing to support a very expensive maintenance contract if we don't continue it. With Win NT and 2K there are ways to keep even accounts that have admin rights restricted. If anyone wants additional information on how to accomplish this, please feel free to e-mail me off-list at [EMAIL PROTECTED] Bruce Barnes ChicagoNetTech / Rinella Internet Services -----Original Message----- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] Behalf Of Dave Sent: Tuesday, March 04, 2003 18:49 To: [EMAIL PROTECTED] Subject: RE: [IMail Forum] OT: Policy Question John, Hostingcontroller.com made that very same request to me today. There is no way I'd let anyone not on my staff access a server via terminal services. If there was no other choice, I'd use Netmeeting with a shared desktop and I'd grant the vendor control while I watched everything they did. > -----Original Message----- > From: [EMAIL PROTECTED] > [mailto:[EMAIL PROTECTED] On Behalf Of > John Tolmachoff > Sent: Tuesday, March 04, 2003 6:35 PM > To: [EMAIL PROTECTED] > Subject: [IMail Forum] OT: Policy Question > > > How many IT admins out there would allow a software vendor > access a server via terminal services to update/upgrade the > vendor's software on the server without their knowledge or oversight? > > We have a client that has allowed this, and it has become an > issue where the client requested us to make some > customizations to the Web screens, but the software vendor > ignored and over wrote with out telling any one. Now the > software vendor is saying they did nothing wrong. > > They made a change based on a user reported problem. > > Hello, we are the IT support. > > Sorry for the OT but this kind of actions by a vendor tick me off. > > John Tolmachoff MCSE, CSSA > IT Manager, Network Engineer > RelianceSoft, Inc. > Fullerton, CA 92835 > www.reliancesoft.com > > > > > To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html > List Archive: > http://www.mail-archive.com/imail_forum%> 40list.ipswitch.com/ > > Knowledge Base/FAQ: > http://www.ipswitch.com/support/IMail/ > > To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/ Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/ To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/ Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/
