Why would they need one? To cover their tracks.

Cheers
Ken

From: James Rankin [mailto:[email protected]]
Sent: Wednesday, 30 November 2011 5:04 PM
To: NT System Admin Issues
Subject: Re: Delegation question

Why would they need to? They already have one

However, anyone with DA access is a risk and a certain amount of trust needs to 
be given. If you're worried about that you need a separate team or individual 
monitoring the access to and use of privileged accounts, whether it be 
resetting passwords, accessing resources, whatever. As long as those with DA 
access have their activities with high-level accounts are logged, then you at 
least have accountability.

However, I'd still feel that helpdesk users with access to DA passwords are 
more of a risk per se than your average third-line support guy. If not for 
nefariousness (possibly the wrong choice of words on my part), then possibly 
for inexperience, naivety or plain stupidity which could lead to them causing 
unforeseen issues when using this sort of privilege.
On 30 November 2011 08:47, Dean Cunningham 
<[email protected]<mailto:[email protected]>> wrote:
And DA's are a different breed of human that would not "resets a DA password 
and uses it for nefarious purposes?"

On Sat, Nov 19, 2011 at 6:05 AM, James Rankin 
<[email protected]<mailto:[email protected]>> wrote:
Thats a bit crazy. What happens when rogue helpdesk guy resets a DA password 
and uses it for nefarious purposes? Prevention is surely better than cure in 
this case. However I have worked at a lot of customers with crazy requirements, 
to be fair.


~ Finally, powerful endpoint security that ISN'T a resource hog! ~

~ <http://www.sunbeltsoftware.com/Business/VIPRE-Enterprise/>  ~

---
To manage subscriptions click here: 
http://lyris.sunbelt-software.com/read/my_forums/
or send an email to 
[email protected]<mailto:[email protected]>
with the body: unsubscribe ntsysadmin



--
"On two occasions...I have been asked, 'Pray, Mr Babbage, if you put into the 
machine wrong figures, will the right answers come out?' I am not able rightly 
to apprehend the kind of confusion of ideas that could provoke such a question."

***** IMPORTANT INFORMATION/DISCLAIMER *****

This document should be read only by those persons to whom it is addressed. If 
you have received this message it was obviously addressed to you and therefore 
you can read it, even it we didn't mean to send it to you. However, if the 
contents of this email make no sense whatsoever then you probably were not the 
intended recipient, or, alternatively, you are a mindless cretin; either way, 
you should immediately kill yourself and destroy your computer (not necessarily 
in that order). Once you have taken this action, please contact us.. no, sorry, 
you can't use your computer, because you just destroyed it, and possibly also 
committed suicide afterwards, but I am starting to digress......

The originator of this email is not liable for the transmission of the 
information contained in this communication. Or are they? Either way it's a 
pretty dull legal query and frankly one I'm not going to dwell on. But should 
you have nothing better to do, please feel free to ruminate on it, and please 
pass on any concrete conclusions should you find them. However, if you pass 
them on via email, be sure to include a disclaimer regarding liability for 
transmission.

In the event that the originator did not send this email to you, then please 
return it to us and attach a scanned-in picture of your mother's brother's wife 
wearing nothing but a kangaroo suit, and we will immediately refund you exactly 
half of what you paid for the can of Whiskas you bought when you went to Pets 
At Home yesterday.

We take no responsibility for non-receipt of this email because we are running 
Exchange 5.5 and everyone knows how glitchy that can be. In the event that you 
do get this message then please note that we take no responsibility for that 
either. Nor will we accept any liability, tacit or implied, for any damage you 
may or may not incur as a result of receiving, or not, as the case may be, from 
time to time, notwithstanding all liabilities implied or otherwise, ummm, hell, 
where was I...umm, no matter what happens, it is NOT, and NEVER WILL BE, OUR 
FAULT!

The comments and opinions expressed herein are my own and NOT those of my 
employer, who, if he knew I was sending emails and surfing the seamier side of 
the Internet, would cut off my manhood and feed it to me for afternoon tea.


~ Finally, powerful endpoint security that ISN'T a resource hog! ~
~ <http://www.sunbeltsoftware.com/Business/VIPRE-Enterprise/>  ~

---
To manage subscriptions click here: 
http://lyris.sunbelt-software.com/read/my_forums/
or send an email to 
[email protected]<mailto:[email protected]>
with the body: unsubscribe ntsysadmin

~ Finally, powerful endpoint security that ISN'T a resource hog! ~
~ <http://www.sunbeltsoftware.com/Business/VIPRE-Enterprise/>  ~

---
To manage subscriptions click here: 
http://lyris.sunbelt-software.com/read/my_forums/
or send an email to [email protected]
with the body: unsubscribe ntsysadmin

Reply via email to