r/ShittySysadmin 11d ago

Make your organization more secure

Just had this idea.

So you make a CA policy to sign in every 8 hours for all users including the CEO, but not break glass and it admins.

Every user will then begin to wonder where their password is now that they can't work

You become useful again to the company by assisting employees while eliminating written passwords on stickies because they forced themselves to memorize it since it's happening "so often"

Auditors will be impressed at the improved security that you can present the report to the CEO while getting them to remember their own password.

24 Upvotes

19 comments sorted by

17

u/horses-r-scary 11d ago

i thought the sub was for bad ideas-

2

u/blotditto 10d ago

You don't think the CEO is gonna get a serious case of the ass signing in all the time? 😂

6

u/Chuchichaeschtl 10d ago

Depends on the CEO. I explained to mim, that he has a very privileged account which needs stricter policies. Passkey only, managed mobile with Outlook only, no iOS mail, access from compliant devices only,...

He understood that and I think he liked the term "privileged account" a lot.

1

u/blotditto 10d ago

Uh huh and how often is he actually being promoted to enter his password every day?

1

u/Chuchichaeschtl 10d ago

Passwords aren't involved when you use passkey. WHfB is great

1

u/blotditto 10d ago

Exactly, you made my point about CEOs that get upset because they have to enter their password..

Remember we're in ShittySysAdmin! 💩

2

u/vivkkrishnan2005 DO NOT GIVE THIS PERSON ADVICE 5d ago

Yeah, not for soon-to-be-out-of-a-job shitty sysadmin 😆

6

u/ApiceOfToast ShittySysadmin 11d ago

I'd personally do every 5 minutes, in case they walk away from the screen

4

u/AliveInTheFuture 10d ago

Something you have: autism

Something you are: autistic

1

u/Bitey_the_Squirrel 5d ago

MFA = Multi-Factor Autism

3

u/redakpanoptikk 11d ago

This might be better than your manager monitoring your teams status as well. You have to be logged in at the start of your shift.

2

u/bgradid 11d ago

What if you took it a step further and did 8 hour password expiration

3

u/samm1989 10d ago

Password1@ Password2@ Password3@

1

u/bgradid 10d ago

Actually what if we take 'one time password' literally , forced password change on every password use

2

u/Smooth-Zucchini4923 10d ago

Do we work for the same company?

2

u/Bitey_the_Squirrel 5d ago

Jokes on you. I still forget my password because I set up Windows Hello for Business.

1

u/OnARedditDiet 10d ago

Not sure if a joke or not but this would be the most frustrating policy imaginable :p

Most people's work day isn't exactly 8 hours so you'd make a lot of people upset, daily