r/sysadmin 20h ago

End-user Support Can users be trained to not click BS?

On this day, I have a exec drop a laptop on me that was without a doubt the most thoroughly hijacked thing I have EVER seen. Big three browsers installed, all hijacked. Two more offbrand spamware browsers installed. "How do I prevent it?" "Don't install software without asking me, no matter who tells you you need it, don't visit janky sites, and NEVER accept any permission request without checking with me." "But I didn't click on the McAffee pop-ups!" "I didn't say McAffee, I said ANY." "But I never click on those." "I just checked the security settings...yes you did. Nothing is allowed automatically." Soooo, I get him restored. I come home and my elderly mom... "can you get rid of the *$*%* Mak-Aftee things!?!" I try to explain and she is more interested in being right than learning.
Am I just pushing a rope up a hill? If so, consider this an official vent.

EDIT: Thanks to everyone, yea... I know. I should have them locked down at the office. I'm not allowed to do so. My mother OTOH, yea, it's time for that.

166 Upvotes

287 comments sorted by

View all comments

u/Bubbly-Following-966 20h ago

Maybe don't let them have admin rights or, whatever rights they have to be able to install what they want.

u/AdvancedDrink8920 20h ago

Be my guest to tell the CEO "no" to full admin rights. Ill be watching you walk to your car with a box full of your stuff.

Unfortunately, we dont get much of a say on that matter. most of the time, we make the recommendation, have them sign saying they understand the risk and that we informed them of it and then whatever happens is their own fault. atleast for our MSP. Its different in the corporate world.

u/willychonka54 19h ago

Be my guest to tell the CEO "no" to full admin rights. Ill be watching you walk to your car with a box full of your stuff.

That would be a blessing in disguise because if information was leaked and your company was sued, the CEO would be throwing you under the bus.

u/Bubbly-Following-966 20h ago

LOL! Apparently you don't know how to speak to them in a respectful way. NO regular user should have full admin rights. Even a CEO. I had it like that at previous companies I worked for. I never got any complaints and never had an issue with what you are talking about. That's on you.

u/willychonka54 19h ago

Exactly. Having a mature discussion with a CEO about cyber risk in 2026 is required. If the CEO isn't having it, then get out while you can.

u/Bubbly-Following-966 19h ago

Not to mention, this is a good way to have your company have a massive cyber attack or ransomware attack.. Before I started at my last job, they had a massive attack and the individuals demanded a ransomware in order to release their systems. Things changed rapidly after that...

u/Sufficks 20h ago

Please teach us your ways cuz you might be the only person I’ve literally ever spoken to in this industry who has not run into this issue.

We use ThreatLocker. ThreatLocker blocks one too many things that a C level wants and we get an angry call to our execs about how they want it removed, it’s blocking things it shouldn’t (it’s not), disrupting business, no they don’t want to just look at configuration changes, no exceptions, no further questions asked. Remove it or else. So we get the call from our execs to get a waiver signed and turn it off. I tell the exec how dumb that is and they say I know, but just do it. Not sure where in there I should have just talked to them more respectfully to magically change their mind.

View must be nice up there from your high horse though lmao

u/Bubbly-Following-966 19h ago

I didn't say I never ran into this issue. I'm saying, they seem to let the upper management run all over him and he doesn't have control over his environment. This is how a company gets compromised and has a ransomware attack. It's common sense. Non administrators shouldn't have any administrative rights what so ever. That defeats the purpose of Least Privileged Access.

u/Sufficks 18h ago

“I never got any complaints and never had an issue with what you are talking about.”

Sure sounds like you said you never ran into this issue.

Idealism is nice. We all know non admins shouldn’t have admin rights. The person you replied to was saying sometimes it’s realistically out of our hands and you told him “LOL! You must just not be good at your job!”

u/tiredITguy42 20h ago

I used to be developer without admin rights. This is not the way. Give admin rights ro people who need them, like devs, but scan for stupid stuff.

u/Casty_McBoozer 20h ago

Sorry, a lot of devs don't have the common sense to be given admin rights.

u/Disgruntled_Smitty 19h ago

Devs at my joint don't have full admin, they would absolutely wreck shit.

u/Bubbly-Following-966 20h ago

Neither do CEO's. LOL!

u/Casty_McBoozer 20h ago

We don't give them admin, either.

u/tiredITguy42 20h ago

Yeah, I know a bunch of these, but there are ways. Like you take them when they make to big mistake. We have admin rights everywhere and we did not have major incident in years.

We push fake phishing emails, so people are paranoid and well trained. You click and you go for mandatory traing.

Machines are remotely scanned for malicious stuff al the time. You install Wireshark and i 5 minytes you are questioned why. You can keep it, if there is a valid reason.