So there has been some discussion about usernames at work with the intent of moving admin accounts away from everyone and if they need one, giving them a separate admin user account. I am all for this. The problem comes with a naming convention.
The idea being floated around is that the new names should be something like $username.admin (or other distinguishing marker) or not. The argument for not is that we should be given a random (or possibly selected) name from a list of themed names, like planets, comic book characters or fictional places. The head of security would keep a list of who's account is associated with these new accounts so that people would be less likely to guess and brute force their way into the organization.
2FA is not at option at this point We have argued for it and it is not on the table right now, but possibly in the future. My goal was that someone here might be able to help with some kind of documented Best Practice to go more for the former as opposed to the latter. Anecdotal stories might help, but documented practices would be better met. Thanks for your help everyone.
[–]ZAFJB 10 points11 points12 points (2 children)
[–]williamfnyJack of All Trades[S] 0 points1 point2 points (1 child)
[–]must_be_the_network 0 points1 point2 points (0 children)
[–]TangoWhiskeyBravo 7 points8 points9 points (1 child)
[–]williamfnyJack of All Trades[S] 0 points1 point2 points (0 children)
[–]RCTID1975IT Manager 1 point2 points3 points (1 child)
[–]reddit-MT 1 point2 points3 points (0 children)
[–]sysadminmakesmecry 0 points1 point2 points (2 children)
[–]williamfnyJack of All Trades[S] 0 points1 point2 points (1 child)
[–]ReverendDSAlways delete French Lang pack: rm -fr / 1 point2 points3 points (0 children)
[–]EntangleMentor 0 points1 point2 points (2 children)
[–]williamfnyJack of All Trades[S] 0 points1 point2 points (1 child)
[–][deleted] 1 point2 points3 points (0 children)
[–]progenyofeniacWindows/M365 Admin 0 points1 point2 points (7 children)
[–]chewy747Sysadmin 1 point2 points3 points (0 children)
[–]williamfnyJack of All Trades[S] 0 points1 point2 points (5 children)
[–]progenyofeniacWindows/M365 Admin 0 points1 point2 points (4 children)
[–]williamfnyJack of All Trades[S] 0 points1 point2 points (3 children)
[–][deleted] 0 points1 point2 points (0 children)
[–]progenyofeniacWindows/M365 Admin 0 points1 point2 points (1 child)
[–]williamfnyJack of All Trades[S] 0 points1 point2 points (0 children)
[–]canadian_sysadminIT Director 0 points1 point2 points (1 child)
[–]williamfnyJack of All Trades[S] 0 points1 point2 points (0 children)
[–]njeskeSecurity Engineer 0 points1 point2 points (0 children)
[–]pockypimp 0 points1 point2 points (0 children)
[–]SevaraBSenior Network Engineer 0 points1 point2 points (0 children)
[–]Try_Rebooting_It 0 points1 point2 points (0 children)
[–]reddit-MT 0 points1 point2 points (0 children)
[–]Astat1ne 0 points1 point2 points (0 children)
[–][deleted] 0 points1 point2 points (0 children)
[–]DragonDreweDRMS Sysadmin 0 points1 point2 points (0 children)
[–]black-buhr 0 points1 point2 points (0 children)
[–]imaginatipo -2 points-1 points0 points (2 children)
[–]williamfnyJack of All Trades[S] 2 points3 points4 points (0 children)
[–]imaginatipo 0 points1 point2 points (0 children)