Home > Ask the Networking Experts > Network administration Questions & Answers > How can I persuade my boss from letting users have administrative access to their machines?
Ask The Networking Expert: Questions & Answers
EMAIL THIS

How can I persuade my boss from letting users have administrative access to their machines?

Lindi Horton EXPERT RESPONSE FROM: Lindi Horton

Pose a Question
Other Networking Categories
Meet all Networking Experts
Become an Expert for this site


Network management news, advice and technical information
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


>
QUESTION POSED ON: 27 July 2007

I have a real hard time trying to persuade my boss that users should not have administrative access to their machines. Talk about fuzz factor! Half of the hours are spent in ICQ, Skype, porn sites, matchmaking, tweaking, CD/DVD-copying, etc. Where can I obtain relevant information that I could cite as argument?



Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


RELATED CONTENT
Network administration
How server virtualization improves efficiency in a client-server model
Why would a computer show drive letters for discs that don't exist?
Formula for proper bandwidth utilization on a T1 line
Open source software for enterprise network management and monitoring
When do applications suffer from poor network performance?
Network configuration flaws block server access and wireless printing
Bandwidth allocation: How can I give a download limit for each user?
Why error reporting ICMP messages include IP headers and datagram data
Network bandwidth calculators: What will be my WAN's link speed?
What VLAN management software supports multiple vendor platforms?

Network Monitoring
Understand Windows tracert output to troubleshoot network connectivity
Network management and monitoring market remains crowded, fragmented
When do applications suffer from poor network performance?
Xangati help desk 'DVR' feature speeds up trouble ticketing resolution
Network change and configuration management vendors see big changes
YouTube, Facebook make bandwidth monitoring best practices challenging
How a new casino manages a giant network with 500 switches, IP voice
How network performance management can save money, boost applications
Return-all-values script: Managing Windows networks using scripts, Part 13
HTTP error code troubleshooting, Part 2: How to use IIS tool WFetch
Network Monitoring Research

Network Performance Management
Virtualization: The next generation of application delivery challenges
New skills emerge for network engineering and administration careers
Improving the performance of Web traffic and application delivery
Network performance management evolution: Involving other IT domains
Formula for proper bandwidth utilization on a T1 line
The link between network management and application delivery
IT automation, automated network management becoming essential
Network management and monitoring market remains crowded, fragmented
Network configuration flaws block server access and wireless printing
Xangati help desk 'DVR' feature speeds up trouble ticketing resolution

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
10-high-day busy period  (SearchNetworking.com)
ACK  (SearchNetworking.com)
baseboard management controller  (SearchNetworking.com)
call failure rate  (SearchNetworking.com)
jam  (SearchNetworking.com)
Jini  (SearchNetworking.com)
maximum segment size  (SearchNetworking.com)
maximum transmission unit  (SearchNetworking.com)
netstat  (SearchNetworking.com)
network tracking tool  (SearchNetworking.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary


As is my favorite engineering answer: it depends. My best advice to you is to learn to speak to your manager as a manager would understand your point of view. For example, you give many technical reasons why users in your organization should not have administrative rights on their machines. However, to create a policy of that nature, you would want to quantify this reasoning in a way that your management team would understand.

First, log how many hours you (your team) spend working on correcting and troubleshooting individual PC problems. By logging the number of hours and incidents, you can first identify if there are recurring instances by a particular user. This user or set of users would be the first to implement a policy of restricted access. Second you can use this number as an indicator for how often you and your team are spent troubleshooting an issue. This time takes you away from other key strategic initiatives that the management teams wants you to focus your time on, e.g. new application rollouts, improving the network backbone, or upgrading servers. In my experience, this falls right in line with the classic 80/20 rule. Eighty percent of the problems are coming from 20% of the users. Perhaps the management team would be more amenable to implementing a policy for those 20% users without affecting the entire user population.

Second, one of your better arguments for enforcing some sort of security policy would be to argue productivity of the users. Non-business critical applications require resources, bandwidth, and are inefficient uses of people's work hours and time. The easiest way to quantify this is to provide metrics around bandwidth consumption for non business critical applications (NetFlow/IPFIX/SFLOW, etc.). Most security related events these days with regard to intellectual property stem from abuses of email and other internal systems. You can argue that productivity is lost for these users and design a strategy to limit their access to certain Web sites.

Of course I would be remiss if I did not warn you that implementing this policy could make you very unpopular in the eyes of your end users. Also be aware that enforcing these policing activities also requires your time and energy. For users with these policies in place, they will request special access to read or get some essential item for their work. They will also be forced to ask you to help them install software that will help them do their jobs. It is essential to understand administrative costs of these types of policies prior to implementing them.




Search and Browse the Expert Answer Center
Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
Browse our Expert Advice



Expert networking advice and tips for IT professionals
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2000 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts