Administrator Password - to tell or not to tell? - TechRepublic
General discussion
March 7, 2008 at 09:50 AM
fruitbat83

Administrator Password – to tell or not to tell?

by fruitbat83 . Updated 17 years, 10 months ago

I am the only IT person in our organisation (25 staff). Obviously, I know the Administrator password but no one else does. In an emergency where someone had to use the Administrator password (for example to gain access to the Server) I have placed the password in a sealed envelope in the Finance fireproof Safe.

I am currently under pressure by the Head of Finance (who is my immediate boss) to tell someone else the Administrator password. I maintain that as it is accessible in the Safe I need not tell someone the password.

I am resisting because all the PCs are locked down (users cannot install anything, change anything etc) and if someone knew the Administrator password, they could install whatever they damn well felt like, which is why the machines are locked down. I want to know what people want installing and why they feel they need it installing.

My boss wishes me to inform just one member of the Senior Managers who “knows about IT”. I know this particular person and feel that armed with the Admin Password she will seek to install software without my agreement, as happened before – she found the old password out and was secretly installing software which I knew nothing about. When I found out she knew the password, I changed it and didn’t tell her, but placed it in the safe.

I feel that as we’re forbidden to tell each other our own logon passwords by Company Policy I shouldn’t be forced to hand out the Admin password willy-nilly, when using it can have massive implications on the system. If I agree to tell this one person, someone else might come along with a gripe that they also need the password and before I know it everyone will be using it.
I feel that there is no solid reason for this lady to have the password until she really, really needs it, and then if I’m not there to assist, she can get it from the safe – why does she need to know it all the time?

My boss argues I’m being a “control freak” about this – but it’s me that will have to fix the PCs when one of our more dopey employees installs something riddled with spyware.

What do you think? What are your own policies regarding the administrator password in your organisation?

This discussion is locked

All Comments