John,

Sorry to reply to this via the list, but I cannot see an e-mail address to
contact you directly.

I have a similar situation with several surgery centers that we are
responsible for.  We do the day-to-day maintenance of the centers and have
to work with a surgical software company that demands administrative access
(albeit not by way of terminal services, but by way of PCAnywhere) to the
servers to make regular updates to their software.

Shortly after we took over the accounts from the person who was doing the
work in-house, we made it a policy to completely block them from access to
any directory except those directories to which they absolutely had to have
access.  We also implemented a policy of assigning every user from within
the company who might have access a separate username and password and
change the passwords on a regular basis.  All access is logged and we are
now in a much better situation to monitor the activity of anyone making
changes to the servers.

It's a bit of a pain in the butt to set up initially and we ran into some
opposition from the client, but we made it very clear that, if we are to be
held responsible and accountable for the operation and maintenance of their
servers, desktops, and networks, then we had to have total security in
place.  Unfortunately, the contract signed by the client gives the vendor
access to the servers at the admin level and they are refusing to support a
very expensive maintenance contract if we don't continue it.

With Win NT and 2K there are ways to keep even accounts that have admin
rights restricted.

If anyone wants additional information on how to accomplish this, please
feel free to e-mail me off-list at [EMAIL PROTECTED]

Bruce Barnes
ChicagoNetTech / Rinella Internet Services


-----Original Message-----
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED] Behalf Of Dave
Sent: Tuesday, March 04, 2003 18:49
To: [EMAIL PROTECTED]
Subject: RE: [IMail Forum] OT: Policy Question


John,

Hostingcontroller.com made that very same request to me today.  There is
no way I'd let anyone not on my staff access a server via terminal
services.    If there was no other choice, I'd use Netmeeting with a
shared desktop and I'd grant the vendor control while I watched
everything they did.

> -----Original Message-----
> From: [EMAIL PROTECTED]
> [mailto:[EMAIL PROTECTED] On Behalf Of
> John Tolmachoff
> Sent: Tuesday, March 04, 2003 6:35 PM
> To: [EMAIL PROTECTED]
> Subject: [IMail Forum] OT: Policy Question
>
>
> How many IT admins out there would allow a software vendor
> access a server via terminal services to update/upgrade the
> vendor's software on the server without their knowledge or oversight?
>
> We have a client that has allowed this, and it has become an
> issue where the client requested us to make some
> customizations to the Web screens, but the software vendor
> ignored and over wrote with out telling any one. Now the
> software vendor is saying they did nothing wrong.
>
> They made a change based on a user reported problem.
>
> Hello, we are the IT support.
>
> Sorry for the OT but this kind of actions by a vendor tick me off.
>
> John Tolmachoff MCSE, CSSA
> IT Manager, Network Engineer
> RelianceSoft, Inc.
> Fullerton, CA  92835
> www.reliancesoft.com
>
>
>
>
> To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html
> List Archive:
> http://www.mail-archive.com/imail_forum%> 40list.ipswitch.com/
>
> Knowledge Base/FAQ:
> http://www.ipswitch.com/support/IMail/
>
>



To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html
List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/
Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/




To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html
List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/
Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/

Reply via email to