Microsoft Employees May Lose Admin Rights
daria42 writes "As Microsoft moves its internal desktop systems to Windows Vista, the company is contemplating whether to change a long running tradition and take away admin rights from its employees in order to improve security." From the article: "'We haven't made that final determination yet. We would like to absolutely look at scenarios where we can look at elements of User Access Control -- that is the feature in Vista -- so that we can start moving in that direction ... It is a tough balance and every company has to decide what is right for them,' said Estberg. However, Estberg said that for the moment, the company will continue to leave the responsibility of installing software with its employees."
"Eat your own dog food".
If Microsoft's access rights model isn't good enough for their own purposes, it isn't good enough for the rest of the world either.
If they were truely confident that it works as they claim it does, they should have had their employees in a more secure and restricted environment years ago.
Slashdot social media options: AIM, ICQ, Yahoo, Jabber and Mobile Text. Why no MySpace?
I don't see why this is a big deal. Average desktop users should not have admin rights -- no?
boxlight
Yes, having the employees run as 'regular' users would be a terrific idea. All the problems that limited user accounts have now would be encountered by those with the most ability to fix them.
Currently, the majority of Microsoft's employees enjoy full admin rights on their desktop PCs, which is an unusual practice in the enterprise space ...
An unusual practice? Where? Most places I know have their users running as admin, because there is still software around that won't function properly if it's not run that way.
If Microsoft forces its employees to run as non-admin users, I think it's a good thing, because maybe it will lessen the amount of crap software that's designed with the assumption that it's going to be run that way.
Unfortunately, that doesn't help the situation with the tons of legacy apps that assume this, and it only takes one important legacy app in a corporate environment to hose the entire security model of non-admin users.
"Ladies and gentlemen, my killbot features Lotus Notes and a machine gun. It is the finest available."
With a huge percentage of the people being developers, these people need full control over their system.
I don't see how they can even implement this scheme.
May be they can take the admin rights from their Managers computers.
It's not uncommon for Linux users (even developers) to use user accounts, because it's very easy to su any administrator tasks. So, maybe Vista will fit this model better, and having developers using user accounts won't be all that ridiculous...
ZuluPad, the wiki notepad on crack
Hell, make them work in monitors the size the average office supplies -- 15" or 17" where I work.
I'm so damn tired of apps that open big windows needlessly in the middle of the screen (MSWord's 'find' for example) covering whatever it is you wanted to actually operate on -- because some programmer had a 29" monitor -- or two -- to work in and never thought about fitting stuff into a real user's working screen.
Open find. Drag stupid window off the text area. Find. Damn, window moved back to the middle. Lather, rinse, repeat.
Sure, the IT department could supply larger monitors. But those are commodities and they're saving their budget for bells and whistles to impress top management.
Windows Media Player 11 *doesn't* need admin rights, hopefully in preparation for Vista.
At least one application has got the idea, even if it is from the company behind the OS.
How many people can read hex if only you and dead people can read hex?
It matters to anyone who was hoping for useful limited user accounts in Vista, because if they have to use them then there's a chance that they'll actually work.
If Microsoft doesn't think Vista's user accounts are usable how did it end up as one of the top features of the whole product :P?
The actual fact they are thinking whether to use it or not makes me fill with doubt. And I really thought they had it right this time (honestly).
Here's a partial list of programs that require admin rights to run (not merely install): ........
PowerDVD
Can't attest to any of the other examples you listed (I don't use WMP, and haven't installed any of the others), but I can attest that I use PowerDVD on my limited-priveleges account just fine, thank you.
Look at the tomato! Isn't it sad? He can't dance! Poor tomato!
If in my college years, when I was working for different companies (as support/admin), they had that feature, I maybe wouldn't have become such a windows hater and concentrate only on unix-like systems.
...
....
....
... just a flashback from my early years of computer support :) and I am not doing anything with customer machines anymore ..... but still, I feel it is a problem ...
....
But then again, it is not enought to take away the admin rights from users completely, you will need a decent way of remote administrating those damn machines.
Before people start trolling on me: yes, you can take away admin rights in 2000/XP (to a cenrtain level) and there are remote tools......
Admin rights should completely go away, the user should not have right to install, modify, not even change the screensaver dammit. And not run programs at all, only from a secure pool of programs.
That includes "i-know-it-all" managers, who tend to fsck everything up, because they know it so-well they are playing in the registry, and deleting folders/etc
Now on the remote tool: the nightmare of a a support/admin person is a multi-level building, where you keep going for all those machines, instead of ssh-ing into them and fixing/installing remotely
Not because they are easy, but they are computer people and not PR monkeys and are probably sick of interacting with all the workers of the companies, who probably do not wash their hands after peeing, and then you have to go and touch 100 keyboars in 100 rooms
Oh well
Ohh, and that's why you have to wear the suit and not cargo pants and something that actually keeps you warm in the server room, or climbing on that roof yagi in the european winter to spot the balloons 5kms away on the rooftop with the compass and the binocular, to re-align the connection
I suspect one of the other big reasons for this is it's cheaper to do a bare-bones re-install when the Windows box goes teets up than to have an admin action every user need that is required on a box where the user is actually treated as a user.
Imagine how many real-life admins you might need to handle the hour to hour needs of a company where access rights in Windows were restricted.
This of course applies to no company that does NOT run Windows. Almost any other company would be able to handle that easily.
Talk about hidden costs.
Luck favors the prepared, darling.
They need to lock down their boxes to make sure that their employees don't discover the utility of free software (like firefox).
Oh _that's_ why they are doing it. That figures. Everyone knows, you always give Linux users root access, so they can install all that great free software. And, equally, we know that if you don't have administrator rights on a Windows box, it's impossible to install Firefox.
And someone gave you an 'insightful'. Geez.
-----
I don't think that can be true. Microsoft would be shooting itself in the foot if its own employees remained in the dark about what's going on in the real world.
You are not alone. This is not normal. None of this is normal.
Is there any reason not to use some kind of virutalization solution, and allow employees to "admin" their images, while forcing user privelidges for the host operating system?
Except for device driver development (even USB and some other stuff would work correctly in a VM), are there any disadvantages?
Are there any OS developer situations that require the performance of native access at the same time as requiring administrator privlidges?
The only arguments I can think of against this are developers that require close hardware access, but with paravirtualization solutions like Xen even thats not a big issue. Well, except on Windows, of course.
WhiteWolf666 an exBush supporter. All you new-school,compassionate,save the children Republicans can rot in hell
Excuse me? The COMPANY deserved it, so you violated your CUSTOMER's copyrights?
You unbelievable, thieving asshole.
-jcr
The only title of honor that a tyrant can grant is "Enemy of the State."
Good idea, but flawed from a security perspective:
If the idea of not having Admin rights is to keep virusX off the network, running Admin in a virtual machine just means virusX runs in the virutal machine & infects the virutal machines on the network: Stuff is still borked bacause all those developers have viruses on the virtual machines...
Note: Personally, I don't see developers wanting to develop in User-Mode. I also don't see why at least the non-developer staff is not running in User-Mode. (OK, realistically I do, but thereotically I don't.)
Even in cases where admin rights are necessary, virii and malware can be mitigated by a combination of tools. With Symantec AV, MS Defender, and a good firewall at the perimeter with content control, the only people who cause problems for me are bored users who get to sites that aren't on the content control deny list. Once I explain to their boss that they're paying me +$100 an hour to clean up a mess that could have been avoided if the employee was doing their god damn job instead of jacking off on someone else's time, the problem usually goes away.
When a workstation blows up, a re-image gets things up an running again in an hour or two.
Even though it's possible to work around the 'dangers' of admin rights, I do agree that it is a problem. Microsoft took a step in the right direction with the Windows XP RunAs. I've found that at my clients who have XP and need admin rights for a particular application, setting up a shortcut that uses the RunAs functionality gets the job done most of the time.
Why can't they "RunAs" for installs (when needed)?
On a similar note, near the end of my mainframe days as a systems programmer & tech support, I worked in a group where everyone worked with God privileges even though they weren't needed 7x24.
I didn't. I usually only had one window open on the 3270 emulator running on OS/2 (this was near the demise) and my coworkers would have tons, but nothing which had regular privileges. If someone (another IS/IT/MIS) staff member went to one of my teammates who were closer physically to them, they'd say, "I don't have that problem." and leave them hanging, not even willing to bring up a "standard" account to see if they could repeat the problem. Once people found out I worked with Joe Q. Citizen privileges, except when needed, I'd either test it or switch to a userid where I could test it.
In the case of Microsoft, if they spent a lot of time working & testing as something other than "Administrator" (userid or privileges), they might get a better appreciation for their users' plights & frustrations. And if they're caught switching back to Administrator unnecessarily, or forgetting to go back to a regular user after fixing a problem as Administrator, then it's time for a public flogging - make them spend the next week as the buildmeister, relieving the person who would earn that privilege when their code breaks the build (is that how it's still decided?).
In terms of those who perform testing, if they're testing as an end-user, how many of them actually need Administrator privileges?