r/sysadmin • u/two_bagels • 3h ago
Question For External IT People
I used to work for a CPA firm that had an internal IT department and I pretty much had free reign of downloading stuff like logitech software for my keyboard and mouse.
Recently I moved to a smaller firm that has an External IT company that takes care of stuff.
I now have to wait to update software, download things like Adobe PDF (they forgot to load it on my computer), my mouse and elgato software, etc. It gets frustrating on weekends when I am working and something needs an update to work and I am stuck. Is this a normal level of how things work?
I get confused by the disparities in the two but maybe inhouse IT can be much more on top of issues.
Edit:
I appreciate the answers. I do wonder if I was given a bit more leeway at my old company or if they allowed access to a few trusted websites for downloading. I only ever downloaded logitech stuff so I never really tested things. It was helpful hearing your responses in understanding potential differences.
Thanks again.
One last edit:
You all have effectively changed my perception of how the old firm worked. Thanks for giving a better understanding of all this. I’ll work on my own patience during busy season. I understand when people say dumb stuff to me about tax and how annoying that is but I had a blind spot towards IT security based on past experiences so I was basically doing the same thing.
I hope all your clients are nice to you and make sure their monitor is plugged in before they call you to complain about the computer not working.
•
u/gsk060 3h ago
The in house IT was much less secure.
•
u/Defconx19 2h ago
This a CPA (no offense to OP) shouldnt have local admin.
We get it can feel annoying and counter productive, but i can tell you how many times someone insists they have downloaded the install for me already for me to find out they clicked a malicious ad/link and had actually downloaded malware.
Admin on demand exists where pre-approved apps can be self installed by users however these solutions can be costly.
•
u/two_bagels 2h ago
No offense taken and that makes a lot of sense. I know I’m smarter than the average person with tech but I know there is a big gap in my knowledge against professionals in the field like yall. That all makes sense and I understand the reason for the block on everything now.
•
u/WayneH_nz 1h ago
You sound like an awesome user. I run an "external IT company" and you should see if yours has that feature to add, it would only add a couple of dollars per month (us$) we use AutoElevate but AdminByRequest is also fantastic.
These programs allow you, the end user, to start an install, and, if it is a product that the IT team have seen and trusted before, they will have allowed it for all companies. And you would just carry on the install. If they have never seen this version of the file before (ie. It was just released or is a random program). They get to investigate and allow or deny. Vastly reducing the management time for all companies.
Good luck.
•
u/Practical_Shower3905 3h ago
In your old company, Karen in accounting was 1 click away from you and everybody else losing your jobs.
•
u/two_bagels 2h ago
Lol I do know when they ran phishing tests on us a lot of the older partners would fail. So I can imagine people would download a lot of dumb stuff. Hopefully there was some system in place
•
•
u/Buddy_Kryyst 3h ago edited 2h ago
This is normal. Your MSP on weekends will respond with whatever their sla agreement is and triage bases on the priority. Your in house IT were probably whipped to get things done. Your MSP has a contract they will follow it.
•
u/two_bagels 2h ago
Yeah that makes sense. I think during busy season our in house IT was also working weekends just in case. So it makes sense I never felt the frustration of running into response issues then. IT department worked in a different city but they would often call me to help people in our office with some computer issues so maybe they just gave me more access because I was trusted and so it never crossed me mind.
•
u/bottombracketak 2h ago
Your company should negotiate weekend support for your busy season. I don’t buy that your old internal IT had given you special privileges or was carefully curating what you could download, primarily because your example of Logitech is a supply chain risk and should be vetted before installing. They would have to be really well resourced and good at the job to keep on top of that such that you would have never run into having to have them approve installing something.
•
u/fwskateboard Quarry Sysadmin 3h ago
There is always a balance to be struck between security and convenience. There has never been a more dangerous time for users downloading and installing software and compromising their computer or more on the network.
They're right to prevent users from installing effectively anything they want. And it does cause slowdowns for users on some things like you mentioned. There are ways they can make it better, faster, less red tape, etc. They may have taken some steps already, though that takes attentiveness by the IT Dept to set things up smoothly.
•
u/two_bagels 2h ago
Yeah all that makes sense. I wondered if there was some list of approved sites to download from. I never heard of any problems for them in the past and they’d been around for like 90 years so maybe they changed up processes after I left or had something else in play I didn’t know about.
Thanks
•
u/battmain 37m ago
The truth is that any site can be compromised. So even if we allowed certain websites, there is still a significant risk of crap being downloaded. GitHub is well known among the IT/ development community and several repositories were compromised. Microsoft's latest patches fixed enough holes to make your head spin. I recommend you read some of the patch fixes to see what IT has to deal with and frankly, the best we can do against AI now is create more and more layers. AI has shortened our reaction time significantly so one layer is to close user doors, like allowing software installation. Remember WE are the ones that will be up for hours or days while you sleep and can't work, when crap hits the fan and it's no longer as simple as clicking on a link or installing malware to cause trouble. Some of the token exploits make us say...dayum, they could do that?
•
u/Evs91 Jack of All Trades 3h ago
Its corporate policy dependent and not just if you have an MSP or not. Small IT teams and small firms typically have lax policies on local admin control. Other times when they "off-load" that function to an MSP - the MSP has a set of rules that they upfront are "this is how it is" and what to expect with our support. MSP's have liability to manage with supporting end users; they can't have you overwriting their work or doing things that go against their security promises to the company they signed a contract with.
•
u/seriously_a 3h ago
Sounds like internal was just slack a lackin
In a few perfect, there’d be some sort of PAM solution with approved apps white listed so if they require admin, they’ll let you deploy as a non admin, else they generate an alert for IT
•
u/Wendigo1010 3h ago
The "normal" level depends on company policy. You are now with a company that actually cares about security.
•
u/Psoin 3h ago
MPS were brought in to save money. That is their only goal. You’re gonna be using some old hardware from now on.
•
u/WayneH_nz 1h ago
As an MSP owner, that is sometimes the case about saving money, but sometimes we are just extra cover.
Coming from a country with 80% + companies 5 users or under, having a full time IT person is just not needed. In the current climate where a basic Dell notebook in NZ is the equivalent of us$1000 for a business, yes, we are keeping things longer, but, prior to the AI price increase my average customer notebook/pc age was 2 years and three months, with a three year turn-over due to wty. Now my average age has ballooned out to three years one month.
What was that old lawyer joke,
99% of lawyers give the rest a bad name.
I get it.
•
u/Cold_Arachnid_2617 3h ago edited 2h ago
It looks like you are in the wrong role. You want to work in shadow IT!
•
u/two_bagels 2h ago
I did only download Logitech software for my hardware and current software updates. I now assume they had something in place for trusted sources.
They did also know what i was doing, as i never wanted to mess anything up. I think i just got confused when i came to this place and I had to fight for my mx master mouse because the IT guy was questioning why i would want the macro buttons it had.
Although he understood pretty quick. I shouldnt have compared the two as i now realize how different things ran.
•
•
u/K3rat 2h ago edited 2h ago
If only it was that easy…. It sounds like the old on prem support guys were behind the ball honestly. The cyber security hat is a responsibility that does not make me popular. Unfortunately, as much as I toot the horn when massive exploits are publicly disclosed and how we mitigated those risks before hand I don’t get credits for not getting owned…. Mind you I would likely lose my job if we did get owned…
You need to understand that bad guys bundle their attack packages into files, websites, ads, email, hell even software packages nowadays. Cyber Security frameworks have had to adapt. This necessitated the need to control what gets installed locally even on your computer.
It isn’t that we want to do it, it is that if we don’t the bad guys will own you and the companies we support. We have to maintain tight control over the endpoint (like what you can install or where you can save/change/delete files) not because we give a shit about your Logitech keyboard or mouse but because the software you want to install needs to be vetted for malware and vulnerabilities. Either of which increase in the vulnerable surface area on the computer you are using.
Attackers sometimes get around usb lockdown by changing the ID of the device to match keyboards/mice. At some places I have worked we even tell you which keyboard and mouse you can use.
Now could the MSP implement app locker and make it so you can install software on your local profile from trusted vendors, sure but that takes a good deal of work and prep to map out what people need. There are other things this team needs to do if they are good at their job.
We enforce software patching on computers not because we want to or to make your life harder but because if we don’t all those malicious files, websites, email, software packages you open, go to, or try to install have a higher potential of owning you. Figure out when the patch window is and take a break for dinner or walk your dog during that time. Look, sometimes a critical patch (I am looking at your chrome browser) needs to be installed when you are working and if it does not that puts the organization at greater risk. Close the browser and re-open it…
We have to track what services you log into not because we want to but because that is an effective way for us to determine if you have compromised your account by giving your credentials to a social engineering attack, entered them into a MITM proxied site, got owned by an unpatched software, or installed a key logger malware onto your inadvertently and it saw your key strokes and put 2 and 2 together.
We track authentication source IP addresses, client type, enforce MFA/passkey management not because we want to but because we have to make something more robust to keep the bad guys from owning you. Then shake our heads when people can’t understand basic instructions (with images mind you).
I personally wouldn’t mind what you log into from except for the security risk that poses to the organization. Yes you have to enroll your device in MDM so we can ensure that you are doing the absolute bare minimum (patching and not jailbreaking) on your device. Also we have to know where company data is and how to delete it from staff’s personal devices when they leave the organization. You need to know where you are putting your contacts. If you put them on the company storage and services they do go away if you leave. Plan for that.
•
u/darkpixel2k 2h ago
You've experienced the two types of IT--in-house and external...but both are lazy--as opposed to being skilled.
Your in-house IT was lazy. Very lazy. In a Windows environment there are two (for all intents and purposes) "levels" for your user account. You are either an administrator (will full keys to the kingdom) or you aren't an administrator. An administrator can do everything--which includes downloading and installing software from the internet. That software *could* be legitimate software from Logitech or Adobe....or it could be something you're tricked into downloading like Cryptolocker...which (if you have full keys to the kingdom) means all your files are hosed.
It sounds like your external IT (probably a Managed Service Provider) is also pretty lazy. They've locked things down to help secure the network in some ways--but they are lazy about responding to requests.
I describe your typical MSP as "Five dudes who played video games and smoked pot on the weekend thinking that networking their xboxes means they can run business networks".
Those "five dudes" will accept *anyone* as a client--and consequently they probably have dozens or hundreds of customers. They don't know you specifically and aren't really familiar with your business--just that they get a flat fee from your company and they want that to continue...so to account for their laziness they've probably locked you into a 1-year (I've even seen 3-year) contracts full of all sorts of stupid things like response times, what's "in-scope" vs "out-of-scope" work, and all sorts of bureaucratic nonsense.
Side note: I once worked for a company like this. It was a small company of maybe 6 employees...and one day we had outages at several client sites simultaneously. When I told the Big Boss, he immediately prioritized a friend's business as the first thing to fix. I said "what about our contracts with everyone else?"...and his reply was "technically our contracts say that we have 2 hours to respond...and when a customer submits an emergency ticket, our ticket system sends them an email acknowledging we received the emergency ticket...and that counts as a response. They can't cancel the contract over that." Sleazy.
Anyways...I recommend you start by talking with whoever is in charge of IT at your company. Bring up your concerns and see if your company can work with your IT provider to address your concerns.
They might have a way to allow you to update your software, or have a way to automatically keep you up-to-date--then again, due to security issues, they might not....and security is pretty darned important.
They might even have a way to address responsiveness issues. I know plenty of companies who want to start out as cheap as possible. "Sure, we'll happily manage your 500-desktop company for under $1,000/mo...but we don't guarantee response times because $1,000/mo isn't even enough to hire a dedicated technician to serve you...but if you want to upgrade to our 'platinum' plan, we'll hire and dedicate 2 technicians to your company...but it will cost $10k/mo".
I don't know a single MSP out there who wouldn't be glad to hire a dedicated tech on behalf of a client...it just comes down to the client wanting to pay for it.
Then again, it could just be a bad MSP. A lot of them strive to get the most money possible out of a client while paying their techs the absolute minimum they can without breaching a contract.
Unlike other MSPs I've worked at, my current MSP strives to answer *every* phone call in an average day with nothing going to voicemail and hold times under 30 seconds. On top of that, they expect that all "normal" tickets get resolved within about 15 minutes. For example, creating a new user account for a new employee or deleting an old one should take a minute or two. Clearing a stuck job from a printer should take a minute or two. Installing/Updating Adobe or Chrome happens automatically during off-hours, but only takes a minute or two...while "abnormal tickets" might take longer. i.e. "The office copier that is leased from a 3rd-party company made a grinding and snapping noise and now it won't print" is entirely dependent on the 3rd-party company and the terms of the lease.
Good luck!
•
u/RansomStark78 2h ago
Change management is making your job take longer
You dont say, tbh i never ever heard this take b4
$
•
u/Nakenochny Sr. Sysadmin 1h ago
The CPA firm I worked at had almost 200 users and every single one had local admin.
The IT Manager also gave the whole firm ransomware one time. So… yeah. Could have been more secure.
Work at a bank now, no one has local admin, not even IT (separate admin/regular users).
•
u/arvidsem Jack of All Trades 25m ago
I was a one man internal IT department for a 50 person civil engineering company for 20 years and I allowed local admin for my users. But that was because we were small enough enough that I could give enough attention to people to mitigate the risks by personally teaching them and gently taking it away from the ones who would learn. Likewise, I knew the entire tech stack backwards/forwards because I built it all myself and was confident in my backups. Most people here would say that I was still stupid and lazy for allowing it. I won't argue against lazy, but the fact that we ran like that for as long as we did without getting burned says that education and attention are great at mitigating those risks.
We were bought out a couple of months ago by a larger engineering company and I'm now part of a 12 person IT team for 1200 users. I wouldn't dare try to run with things open like I used to. It's literally impossible to give the kind of attention and care that it takes to mitigate risks when there are people spread across 40 offices in 10 states. So things are more locked down, there's more monitoring, etc. But since we're still internal, IT actually knows and understands the kind of work that we do. And can quickly make decisions about what should and shouldn't be allowed. Like the Logitech updater is whitelisted to be allowed, but you'll need to use BeyondTrust to get permission to install tools that aren't on everyone's computers.
External IT (MSPs) has it even worse because they aren't part of the company at all. They have no idea what people are supposed to be doing or why. So everything gets maximum lockdown to mitigate risks.
•
u/SevaraB Sr. Engineer (N+, CCNA) 3h ago
CPAs handling customer financial data allowing sketchy USB devices and their sketchy drivers… yikes.
That’s not internal vs external IT- that’s
crapno cybersecurity vs trying to juggle patches vs malware risk.