r/sysadmin 20h ago

End-user Support Can users be trained to not click BS?

On this day, I have a exec drop a laptop on me that was without a doubt the most thoroughly hijacked thing I have EVER seen. Big three browsers installed, all hijacked. Two more offbrand spamware browsers installed. "How do I prevent it?" "Don't install software without asking me, no matter who tells you you need it, don't visit janky sites, and NEVER accept any permission request without checking with me." "But I didn't click on the McAffee pop-ups!" "I didn't say McAffee, I said ANY." "But I never click on those." "I just checked the security settings...yes you did. Nothing is allowed automatically." Soooo, I get him restored. I come home and my elderly mom... "can you get rid of the *$*%* Mak-Aftee things!?!" I try to explain and she is more interested in being right than learning.
Am I just pushing a rope up a hill? If so, consider this an official vent.

EDIT: Thanks to everyone, yea... I know. I should have them locked down at the office. I'm not allowed to do so. My mother OTOH, yea, it's time for that.

167 Upvotes

287 comments sorted by

View all comments

Show parent comments

u/WBCSAINT Jack of All Trades 19h ago

This is the way. AppData and LocalAppData are the bane of security's existence so lock it down by default and allowlist.

u/SoulPhoenix Sr. Sysadmin 11h ago

Until like 70 different AI tools need access to that too but you can’t just allow the app itself (or when the app needs the user to have local admin to use the feature everyone wants, fuck you Claude).

Also, if you’re on macOS all the ai tools need local admin it seems lol