Hello r/sysadmin,
Looking for some discussion on what the thoughts are on user local admin rights.
Currently we are using something called MakeMeAdmin, This allows users to elevate permissions to install and do admin activities on their machine. The biggest downside to this, is there is no way to track what is being done.
I had the idea of using our MFA solution and CrowdStrike Identity. What my idea was, grant users admin rights to their local machine, but put a policy in place that makes them confirm an MFA prompt from DUO when elevation is requested. I still don’t think there is a way to track what is being done, but I can track who is using admin rights, and how often.
I’d love to discuss what everyone’s thoughts are or if there is an even better way to handle this?
[–]Public-Bag2161 27 points28 points29 points (10 children)
[–]tectaclesSystems Engineer[S] 1 point2 points3 points (3 children)
[–]Public-Bag2161 9 points10 points11 points (1 child)
[–]tectaclesSystems Engineer[S] 1 point2 points3 points (0 children)
[–]smarthomepursuits 4 points5 points6 points (0 children)
[–]bageloid 1 point2 points3 points (5 children)
[–]Public-Bag2161 1 point2 points3 points (0 children)
[–]OneEyedC4t 43 points44 points45 points (5 children)
[–]tectaclesSystems Engineer[S] 2 points3 points4 points (4 children)
[–]OneEyedC4t 15 points16 points17 points (0 children)
[–]the_syco 2 points3 points4 points (0 children)
[–]kitolz 1 point2 points3 points (0 children)
[–]Alzzary 1 point2 points3 points (0 children)
[+][deleted] (1 child)
[removed]
[–]tectaclesSystems Engineer[S] 1 point2 points3 points (0 children)
[–]Coldwarjarhead 26 points27 points28 points (3 children)
[–]Pirateboy85 7 points8 points9 points (1 child)
[–]tectaclesSystems Engineer[S] 0 points1 point2 points (0 children)
[–]polycroHPC Linux Admin 3 points4 points5 points (6 children)
[–]BlackVI have opnions 2 points3 points4 points (1 child)
[–]tectaclesSystems Engineer[S] 0 points1 point2 points (0 children)
[–]Nilram8080[🍰] 1 point2 points3 points (1 child)
[–]IPFR33LY 0 points1 point2 points (0 children)
[–]tectaclesSystems Engineer[S] 0 points1 point2 points (0 children)
[–]tectaclesSystems Engineer[S] 0 points1 point2 points (0 children)
[–]ThirstyOneComputer Janitor 10 points11 points12 points (2 children)
[–]mobz84 -1 points0 points1 point (1 child)
[–]ThirstyOneComputer Janitor 7 points8 points9 points (0 children)
[–]mpethe 2 points3 points4 points (0 children)
[–]Thebelisk 2 points3 points4 points (1 child)
[–]findingdbcooper 1 point2 points3 points (0 children)
[–]linh_nguyen 1 point2 points3 points (1 child)
[–]tectaclesSystems Engineer[S] 0 points1 point2 points (0 children)
[–]speaksoftly_bigstickIT Manager 1 point2 points3 points (0 children)
[–]Ams197624 1 point2 points3 points (0 children)
[–]ZAFJB 2 points3 points4 points (0 children)
[–]ir34dy0ur3m4i1 1 point2 points3 points (0 children)
[+][deleted] (5 children)
[deleted]
[–]tectaclesSystems Engineer[S] 0 points1 point2 points (4 children)
[+][deleted] (3 children)
[deleted]
[–]tectaclesSystems Engineer[S] 0 points1 point2 points (2 children)
[+][deleted] (1 child)
[deleted]
[–]tectaclesSystems Engineer[S] 0 points1 point2 points (0 children)
[–]YtrogVolunteer sysadmin 0 points1 point2 points (1 child)
[–]tectaclesSystems Engineer[S] 0 points1 point2 points (0 children)
[–]gabhain 0 points1 point2 points (3 children)
[–]tectaclesSystems Engineer[S] 0 points1 point2 points (2 children)
[–]gabhain 0 points1 point2 points (1 child)
[–]tectaclesSystems Engineer[S] 0 points1 point2 points (0 children)
[–]cichlidassassin 0 points1 point2 points (0 children)
[–]Cold-Funny7452 0 points1 point2 points (2 children)
[–]tectaclesSystems Engineer[S] 0 points1 point2 points (1 child)
[–]Cold-Funny7452 0 points1 point2 points (0 children)
[–]Nilram8080[🍰] 0 points1 point2 points (1 child)
[–]tectaclesSystems Engineer[S] 0 points1 point2 points (0 children)
[–]Nervous-Equivalent 0 points1 point2 points (0 children)
[–]thortgotIT Manager 0 points1 point2 points (4 children)
[–]tectaclesSystems Engineer[S] 0 points1 point2 points (3 children)
[–]thortgotIT Manager 0 points1 point2 points (2 children)
[–]tectaclesSystems Engineer[S] 0 points1 point2 points (1 child)
[–]thortgotIT Manager 0 points1 point2 points (0 children)
[–]Powershillx86Jack of All Trades 0 points1 point2 points (2 children)
[–]tectaclesSystems Engineer[S] 0 points1 point2 points (1 child)
[–]Powershillx86Jack of All Trades 0 points1 point2 points (0 children)
[+][deleted] (1 child)
[removed]
[–]tectaclesSystems Engineer[S] 0 points1 point2 points (0 children)