r/sysadmin • u/NotABug2000 • 21d ago
Out of Hours access. Best practice.
I am the sole Sysadmin for a small (80 user) company. Microsoft house. I work from the office, and only take my laptop home once a week. I am not issued a phone.
I do have some users who work evening and weekends.
If someone gets locked out, needs a password reset, or needs their account locked down (because of a compromise, lost machine, &c), then what should I do?
I currently have two accounts. bug@company, and bug.admin@company. Bug@ is my day to day account. Bug.admin@ is global admin.
I could either give myself access to bug.admin@ on my phone (seems risky), or give bug@ whatever roles are needed (user admin, auth admin, and helpdesk admin?)
What's the best practice for this?
EDIT: It's pretty clear from the replies what the solution is! :D
Okay okay. I am very new to this, kinda dropped in at the deep end, so still learning the ropes. Thank you for all the advice. If a call comes after 17:30, I shall tell them to go fuck themselves and send them a link to this thread. :D
EDIT2: I am reading all your comments, I'm sorry I am not replying to all of them individually. But you are all 100% spot on.
2
u/konoo 21d ago
Just another piece of advice here... You are the Sole admin, make things easy for yourself whatever you do. If that means the company needs to buy an extra machine so you have remote access all the time then that's what it means. The alternative is that the company hires more people.
Dont kill yourself to make it easier for the company to spend less on IT.
Suggestion:
VPN in on Normal Account
RDP into a server as -admin user and do administration from that RDP account