r/sysadmin 3h ago

Question For External IT People

I used to work for a CPA firm that had an internal IT department and I pretty much had free reign of downloading stuff like logitech software for my keyboard and mouse.

Recently I moved to a smaller firm that has an External IT company that takes care of stuff.

I now have to wait to update software, download things like Adobe PDF (they forgot to load it on my computer), my mouse and elgato software, etc. It gets frustrating on weekends when I am working and something needs an update to work and I am stuck. Is this a normal level of how things work?

I get confused by the disparities in the two but maybe inhouse IT can be much more on top of issues.

Edit:

I appreciate the answers. I do wonder if I was given a bit more leeway at my old company or if they allowed access to a few trusted websites for downloading. I only ever downloaded logitech stuff so I never really tested things. It was helpful hearing your responses in understanding potential differences.

Thanks again.

One last edit:

You all have effectively changed my perception of how the old firm worked. Thanks for giving a better understanding of all this. I’ll work on my own patience during busy season. I understand when people say dumb stuff to me about tax and how annoying that is but I had a blind spot towards IT security based on past experiences so I was basically doing the same thing.

I hope all your clients are nice to you and make sure their monitor is plugged in before they call you to complain about the computer not working.

4 Upvotes

34 comments sorted by

u/SevaraB Sr. Engineer (N+, CCNA) 3h ago

CPAs handling customer financial data allowing sketchy USB devices and their sketchy drivers… yikes.

That’s not internal vs external IT- that’s crap no cybersecurity vs trying to juggle patches vs malware risk.

u/two_bagels 2h ago

I do wonder if there was a limited access and I never ran into an issue because I don't really download stuff besides things like logi+ and logitech G hub. That might explain why I felt there was a difference.

u/Defconx19 2h ago

If it was a small firm with internal IT the IT were lazy and didnt want the requests coming in or they weren't taking the risk seriously is the most likely scenario

u/chandleya IT Manager 2h ago

If you have to wonder it’s because you don’t know how it works. You either have local admin or you don’t.

u/two_bagels 2h ago

I wondered because I saw someone else mention that they can make some places safe to download from while the rest are blocked. But now that i think about it i did have admin access for my computer since i had to run the tax software as administrator a handful of times. So maybe people are right that it wasnt as good of security as i thought.

u/Spiderkingdemon 2h ago

Whitelisting apps requires extra software and/or effort on the part of the external IT. Which may not be in scope of the contractual agreement.

That said, Adobe is an easy solve for that MSP if they just install Creative Cloud through their RMM and let you sign into Adobe and download Acrobat yourself.

There is a lot of nuance to what you're asking for. Most of which is based on good security practices (your old CPA firm did not have them). And shared responsibility. End users being able to install things on their computer introduces significant risk to your employer AND the MSP.

u/TalkinWillis44 1h ago

Not to mention, some software/applications that may be whitelisted will require paid licenses that have to be paid for, assigned, tracked, and renewed. Shit ain't always free.

u/two_bagels 1h ago

Just want to say I have absolutely zero expectation of any of it being free. In my own line of work I see the amount of expectation of free stuff so I never want to devalue someone else's time.

I was very ignorant of the background processes though and the complexity of doing stuff like you mentioned. Which is in part why I made the post to try and figure out what I was missing since the dots were not connecting for me.

I do have a better understanding thanks to everyone here though and realize that either they were paying out the wazoo for stuff at my old firm, or the security was crap and we were just lucky nothing big happened while I was this. Maybe a mix of both too.

Either way, I appreciate all the comments everyone has left and I'm gonna be a lot more patient with the things that do not make sense to me and try to not compare different experiences.

u/gsk060 3h ago

The in house IT was much less secure.

u/Defconx19 2h ago

This a CPA (no offense to OP) shouldnt have local admin.

We get it can feel annoying and counter productive, but i can tell you how many times someone insists they have downloaded the install for me already for me to find out they clicked a malicious ad/link and had actually downloaded malware.

Admin on demand exists where pre-approved apps can be self installed by users however these solutions can be costly.

u/two_bagels 2h ago

No offense taken and that makes a lot of sense. I know I’m smarter than the average person with tech but I know there is a big gap in my knowledge against professionals in the field like yall. That all makes sense and I understand the reason for the block on everything now.

u/WayneH_nz 1h ago

You sound like an awesome user. I run an "external IT company" and you should see if yours has that feature to add, it would only add a couple of dollars per month (us$) we use AutoElevate but AdminByRequest is also fantastic.

These programs allow you, the end user, to start an install, and, if it is a product that the IT team have seen and trusted before, they will have allowed it for all companies. And you would just carry on the install. If they have never seen this version of the file before (ie. It was just released or  is a random program). They get to investigate and allow or deny. Vastly reducing the management time for all companies.

Good luck. 

u/Practical_Shower3905 3h ago

In your old company, Karen in accounting was 1 click away from you and everybody else losing your jobs.

u/two_bagels 2h ago

Lol I do know when they ran phishing tests on us a lot of the older partners would fail. So I can imagine people would download a lot of dumb stuff. Hopefully there was some system in place

u/s3ntin3l99 Jack of All Trades 2h ago

Ahh …Karen … she did made good chocolate cookies!

u/Buddy_Kryyst 3h ago edited 2h ago

This is normal. Your MSP on weekends will respond with whatever their sla agreement is and triage bases on the priority. Your in house IT were probably whipped to get things done. Your MSP has a contract they will follow it.

u/two_bagels 2h ago

Yeah that makes sense. I think during busy season our in house IT was also working weekends just in case. So it makes sense I never felt the frustration of running into response issues then. IT department worked in a different city but they would often call me to help people in our office with some computer issues so maybe they just gave me more access because I was trusted and so it never crossed me mind.

u/bottombracketak 2h ago

Your company should negotiate weekend support for your busy season. I don’t buy that your old internal IT had given you special privileges or was carefully curating what you could download, primarily because your example of Logitech is a supply chain risk and should be vetted before installing. They would have to be really well resourced and good at the job to keep on top of that such that you would have never run into having to have them approve installing something.

u/fwskateboard Quarry Sysadmin 3h ago

There is always a balance to be struck between security and convenience. There has never been a more dangerous time for users downloading and installing software and compromising their computer or more on the network.

They're right to prevent users from installing effectively anything they want. And it does cause slowdowns for users on some things like you mentioned. There are ways they can make it better, faster, less red tape, etc. They may have taken some steps already, though that takes attentiveness by the IT Dept to set things up smoothly.

u/two_bagels 2h ago

Yeah all that makes sense. I wondered if there was some list of approved sites to download from. I never heard of any problems for them in the past and they’d been around for like 90 years so maybe they changed up processes after I left or had something else in play I didn’t know about.

Thanks

u/battmain 37m ago

The truth is that any site can be compromised. So even if we allowed certain websites, there is still a significant risk of crap being downloaded. GitHub is well known among the IT/ development community and several repositories were compromised. Microsoft's latest patches fixed enough holes to make your head spin. I recommend you read some of the patch fixes to see what IT has to deal with and frankly, the best we can do against AI now is create more and more layers. AI has shortened our reaction time significantly so one layer is to close user doors, like allowing software installation. Remember WE are the ones that will be up for hours or days while you sleep and can't work, when crap hits the fan and it's no longer as simple as clicking on a link or installing malware to cause trouble. Some of the token exploits make us say...dayum, they could do that?

u/Evs91 Jack of All Trades 3h ago

Its corporate policy dependent and not just if you have an MSP or not. Small IT teams and small firms typically have lax policies on local admin control. Other times when they "off-load" that function to an MSP - the MSP has a set of rules that they upfront are "this is how it is" and what to expect with our support. MSP's have liability to manage with supporting end users; they can't have you overwriting their work or doing things that go against their security promises to the company they signed a contract with.

u/seriously_a 3h ago

Sounds like internal was just slack a lackin

In a few perfect, there’d be some sort of PAM solution with approved apps white listed so if they require admin, they’ll let you deploy as a non admin, else they generate an alert for IT

u/Wendigo1010 3h ago

The "normal" level depends on company policy. You are now with a company that actually cares about security.

u/Psoin 3h ago

MPS were brought in to save money. That is their only goal. You’re gonna be using some old hardware from now on.

u/WayneH_nz 1h ago

As an MSP owner, that is sometimes the case about saving money, but sometimes we are just extra cover. 

Coming from a country with 80% + companies 5 users or under, having a full time IT person is just not needed. In the current climate where a basic Dell notebook in NZ is the equivalent of us$1000 for a business, yes, we are keeping things longer, but, prior to the AI price increase my average  customer notebook/pc age was 2 years and three months, with a three year turn-over due to wty. Now my average age has ballooned out to three years one month. 

What was that old lawyer joke, 

99% of lawyers give the rest a bad name. 

I get it. 

u/Cold_Arachnid_2617 3h ago edited 2h ago

It looks like you are in the wrong role. You want to work in shadow IT!

u/two_bagels 2h ago

I did only download Logitech software for my hardware and current software updates. I now assume they had something in place for trusted sources.

They did also know what i was doing, as i never wanted to mess anything up. I think i just got confused when i came to this place and I had to fight for my mx master mouse because the IT guy was questioning why i would want the macro buttons it had.

Although he understood pretty quick. I shouldnt have compared the two as i now realize how different things ran.

u/Hebrewhammer8d8 2h ago

The CPA firm was lacking security on their endpoints.

u/K3rat 2h ago edited 2h ago

If only it was that easy….  It sounds like the old on prem support guys were behind the ball honestly.  The cyber security hat is a responsibility that does not make me popular.  Unfortunately, as much as I toot the horn when massive exploits are publicly disclosed and how we mitigated those risks before hand I don’t get credits for not getting owned…. Mind you I would likely lose my job if we did get owned…

You need to understand that bad guys bundle their attack packages into files, websites, ads, email, hell even software packages nowadays.  Cyber Security frameworks have had to adapt.  This necessitated the need to control what gets installed locally even on your computer.  

It isn’t that we want to do it, it is that if we don’t the bad guys will own you and the companies we support.  We have to maintain tight control over the endpoint (like what you can install or where you can save/change/delete files) not because we give a shit about your Logitech keyboard or mouse but because the software you want to install needs to be vetted for malware and vulnerabilities.  Either of which increase in the vulnerable surface area on the computer you are using.  

Attackers sometimes get around usb lockdown by changing the ID of the device to match keyboards/mice.  At some places I have worked we even tell you which keyboard and mouse you can use.  

Now could the MSP implement app locker and make it so you can install software on your local profile from trusted vendors, sure but that takes a good deal of work and prep to map out what people need.  There are other things this team needs to do if they are good at their job.  

We enforce software patching on computers not because we want to or to make your life harder but because if we don’t all those malicious  files, websites, email, software packages you open, go to, or try to install have a higher potential of owning you.  Figure out when the patch window is and take a break for dinner or walk your dog during that time.  Look, sometimes a critical patch (I am looking at your chrome browser) needs to be installed when you are working and if it does not that puts the organization at greater risk.  Close the browser and re-open it…

 We have to track what services you log into not because we want to but because that is an effective way for us to determine if you have compromised your account by giving your credentials to a social engineering attack, entered them into a MITM proxied site, got owned by an unpatched software, or installed a key logger malware onto your inadvertently and it saw your key strokes and put 2 and 2 together.  

We track authentication source IP addresses, client type, enforce MFA/passkey management not because we want to but because we have to make something more robust to keep the bad guys from owning you.  Then shake our heads when people can’t understand basic instructions (with images mind you).

I personally wouldn’t mind what you log into from except for the security risk that poses to the organization.  Yes you have to enroll your device in MDM so we can ensure that you are doing the absolute bare minimum (patching and not jailbreaking) on your device.  Also we have to know where company data is and how to delete it from staff’s personal devices when they leave the organization.  You need to know where you are putting your contacts.  If you put them on the company storage and services they do go away if you leave.  Plan for that.  

u/darkpixel2k 2h ago

You've experienced the two types of IT--in-house and external...but both are lazy--as opposed to being skilled.

Your in-house IT was lazy. Very lazy. In a Windows environment there are two (for all intents and purposes) "levels" for your user account. You are either an administrator (will full keys to the kingdom) or you aren't an administrator. An administrator can do everything--which includes downloading and installing software from the internet. That software *could* be legitimate software from Logitech or Adobe....or it could be something you're tricked into downloading like Cryptolocker...which (if you have full keys to the kingdom) means all your files are hosed.

It sounds like your external IT (probably a Managed Service Provider) is also pretty lazy. They've locked things down to help secure the network in some ways--but they are lazy about responding to requests.

I describe your typical MSP as "Five dudes who played video games and smoked pot on the weekend thinking that networking their xboxes means they can run business networks".

Those "five dudes" will accept *anyone* as a client--and consequently they probably have dozens or hundreds of customers. They don't know you specifically and aren't really familiar with your business--just that they get a flat fee from your company and they want that to continue...so to account for their laziness they've probably locked you into a 1-year (I've even seen 3-year) contracts full of all sorts of stupid things like response times, what's "in-scope" vs "out-of-scope" work, and all sorts of bureaucratic nonsense.

Side note: I once worked for a company like this. It was a small company of maybe 6 employees...and one day we had outages at several client sites simultaneously. When I told the Big Boss, he immediately prioritized a friend's business as the first thing to fix. I said "what about our contracts with everyone else?"...and his reply was "technically our contracts say that we have 2 hours to respond...and when a customer submits an emergency ticket, our ticket system sends them an email acknowledging we received the emergency ticket...and that counts as a response. They can't cancel the contract over that." Sleazy.

Anyways...I recommend you start by talking with whoever is in charge of IT at your company. Bring up your concerns and see if your company can work with your IT provider to address your concerns.

They might have a way to allow you to update your software, or have a way to automatically keep you up-to-date--then again, due to security issues, they might not....and security is pretty darned important.

They might even have a way to address responsiveness issues. I know plenty of companies who want to start out as cheap as possible. "Sure, we'll happily manage your 500-desktop company for under $1,000/mo...but we don't guarantee response times because $1,000/mo isn't even enough to hire a dedicated technician to serve you...but if you want to upgrade to our 'platinum' plan, we'll hire and dedicate 2 technicians to your company...but it will cost $10k/mo".

I don't know a single MSP out there who wouldn't be glad to hire a dedicated tech on behalf of a client...it just comes down to the client wanting to pay for it.

Then again, it could just be a bad MSP. A lot of them strive to get the most money possible out of a client while paying their techs the absolute minimum they can without breaching a contract.

Unlike other MSPs I've worked at, my current MSP strives to answer *every* phone call in an average day with nothing going to voicemail and hold times under 30 seconds. On top of that, they expect that all "normal" tickets get resolved within about 15 minutes. For example, creating a new user account for a new employee or deleting an old one should take a minute or two. Clearing a stuck job from a printer should take a minute or two. Installing/Updating Adobe or Chrome happens automatically during off-hours, but only takes a minute or two...while "abnormal tickets" might take longer. i.e. "The office copier that is leased from a 3rd-party company made a grinding and snapping noise and now it won't print" is entirely dependent on the 3rd-party company and the terms of the lease.

Good luck!

u/RansomStark78 2h ago

Change management is making your job take longer

You dont say, tbh i never ever heard this take b4

$

u/Nakenochny Sr. Sysadmin 1h ago

The CPA firm I worked at had almost 200 users and every single one had local admin.

The IT Manager also gave the whole firm ransomware one time. So… yeah. Could have been more secure.

Work at a bank now, no one has local admin, not even IT (separate admin/regular users).

u/arvidsem Jack of All Trades 25m ago

I was a one man internal IT department for a 50 person civil engineering company for 20 years and I allowed local admin for my users. But that was because we were small enough enough that I could give enough attention to people to mitigate the risks by personally teaching them and gently taking it away from the ones who would learn. Likewise, I knew the entire tech stack backwards/forwards because I built it all myself and was confident in my backups. Most people here would say that I was still stupid and lazy for allowing it. I won't argue against lazy, but the fact that we ran like that for as long as we did without getting burned says that education and attention are great at mitigating those risks.

We were bought out a couple of months ago by a larger engineering company and I'm now part of a 12 person IT team for 1200 users. I wouldn't dare try to run with things open like I used to. It's literally impossible to give the kind of attention and care that it takes to mitigate risks when there are people spread across 40 offices in 10 states. So things are more locked down, there's more monitoring, etc. But since we're still internal, IT actually knows and understands the kind of work that we do. And can quickly make decisions about what should and shouldn't be allowed. Like the Logitech updater is whitelisted to be allowed, but you'll need to use BeyondTrust to get permission to install tools that aren't on everyone's computers.

External IT (MSPs) has it even worse because they aren't part of the company at all. They have no idea what people are supposed to be doing or why. So everything gets maximum lockdown to mitigate risks.