"Best practice" for administering users' accounts

  • Thread starter Thread starter Heinrich Moser
  • Start date Start date
H

Heinrich Moser

Hi!

Scenario: You are administrator in a small Windows network.

Problem: Sometimes you need to log on as a specific user on that
user's PC, because you need to configure something (that the user
cannot do himself) or fix a problem that only occurs in his account,
etc. Ideally, this should be done while the user is not there so that
you don't disturb his work.

Unfortunately, Windows does not allow an administrator to log on as
another user without knowing his password, so what is the
"recommended" way of solving this problem?

- Ask all users to give you their passwords and store them in a safe
place?

- Do your maintainance work in the evening and ask the user to stay
logged in on his PC when leaving?

- Reset the user's password and tell him to change it back afterwards?

- Something else? Somehow, all of the above options have their
drawbacks and none is really satisfying...

Greetings,
Heinzi
 
Heinrich Moser said:
Hi!

Scenario: You are administrator in a small Windows network.

Problem: Sometimes you need to log on as a specific user on that
user's PC, because you need to configure something (that the user
cannot do himself) or fix a problem that only occurs in his account,
etc. Ideally, this should be done while the user is not there so that
you don't disturb his work.

Unfortunately, Windows does not allow an administrator to log on as
another user without knowing his password, so what is the
"recommended" way of solving this problem?

- Ask all users to give you their passwords and store them in a safe
place?

- Do your maintainance work in the evening and ask the user to stay
logged in on his PC when leaving?

- Reset the user's password and tell him to change it back afterwards?

- Something else? Somehow, all of the above options have their
drawbacks and none is really satisfying...

Greetings,
Heinzi
Override (reset) their password ; they probably don't change it frequently
enough anyway. Storing their passwords adds a new security risk so that is
the worst choice of all.
 
- Reset the user's password and tell him to change it back afterwards?

And then change it to another password, mark it as much change next
login, then tell the person the password.

--

Leythos
- Igitur qui desiderat pacem, praeparet bellum.
- Calling an illegal alien an "undocumented worker" is like calling a
drug dealer an "unlicensed pharmacist"
(e-mail address removed) (remove 999 for proper email address)
 
Back
Top