• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 172
  • Last Modified:

Login to computer through Admin Priviligies

Hi all,
Just wanted a bit more insight on what are good and bads about logging into your work computer through admin privileges? means I know Admin account has lot of security privileges which can be exploited but is it really a big threat? I though having an Administrator user account (local/domain) is much bigger threat then this.
the reason to login to work computer with admin privileges is because to run applications like sccm, sql, sharepoint etc....
0
Leo
Asked:
Leo
2 Solutions
 
McKnifeCommented:
Please read my article https://www.experts-exchange.com/articles/24599/Free-yourself-of-your-administrative-account.html where I show a way out of this dilemma.
And please explain "I though having an Administrator user account (local/domain) is much bigger threat then this." - I don't understand what "this" should mean as "this" should be the same.
0
 
LeoAuthor Commented:
Thanks for that article, now if I want to run a security audit across the network, is there a tool which can be used?
0
 
McKnifeCommented:
What should that audit find out exactly?
0
Improve Your Query Performance Tuning

In this FREE six-day email course, you'll learn from Janis Griffin, Database Performance Evangelist. She'll teach 12 steps that you can use to optimize your queries as much as possible and see measurable results in your work. Get started today!

 
LeoAuthor Commented:
Security holes in infrastructure , people who are using admin accounts to log on to there computers, any batch scripts which are running, service accounts whose passwords haven't been changed and general overall security health of infrastructure.
thanks.
0
 
McKnifeCommented:
Sorry, but this is really a totally different question, in fact, a set of questions. Please start new threads.
0
 
QlemoBatchelor, Developer and EE Topic AdvisorCommented:
Even if you leave attacks aside, you need to consider accidental actions like changing/deleting important files from protected areas. As non-admin you at least need another confirmation. On the other side, if you get conifrmation prompts for almost every action you have to take, they are useless ;-).
0
 
McKnifeCommented:
"As non-admin you at least need another confirmation" - as admin, too, at least when UAC is at default level.
0
 
Mike TLeading EngineerCommented:
Hi,

Short answer is that you need to ban logging in as the following on workstations:

domain admin
local admin

Users need restricted accounts. Power users need power accounts. No-one but no-one needs to be domain admin and logon to a workstation. Ever.
Even on servers limit it to a handful of trusted, authorised and competent (ideally certified) people. If they are not certified, go on training and get it. There's no excuse.

Always go for "least privilege" which means give people only enough permissions to do the things they are meant to be allowed and no more.

As for SCCM, well it does the permissions for you. You still don't need to logon as admin to make it work. In fact it's not going to help at all because it uses Local System which beats even domain admin anyway.

As for an auditing tool, create a new question and I'll try and remember what I've used in the past.

Mike
0
 
McKnifeCommented:
@Leo
I see you didn't ask any related questions, yet. You should. The additional questions reach far beyond this one.
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

Featured Post

Cloud Class® Course: Certified Penetration Testing

This CPTE Certified Penetration Testing Engineer course covers everything you need to know about becoming a Certified Penetration Testing Engineer. Career Path: Professional roles include Ethical Hackers, Security Consultants, System Administrators, and Chief Security Officers.

Tackle projects and never again get stuck behind a technical roadblock.
Join Now