Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Bunni-kat
May 25, 2010

Service Desk B-b-bunny...
How can-ca-caaaaan I
help-p-p-p you?
I’m in day 2 of 3 in itil v3 training, and people just referenced reddit.

Adbot
ADBOT LOVES YOU

devmd01
Mar 7, 2006

Elektronik
Supersonik

Irritated Goat posted:

Yeah, we've got a lot of it done that way but renaming\setting the password for the local admin user has been oddly flaky.

That's because setting the local admin password via GPO is insecure and deprecated. Use LAPS.

https://support.microsoft.com/en-us/help/2962486/ms14-025-vulnerability-in-group-policy-preferences-could-allow-elevati

Bob Morales
Aug 18, 2006


Just wear the fucking mask, Bob

I don't care how many people I probably infected with COVID-19 while refusing to wear a mask, my comfort is far more important than the health and safety of everyone around me!

Inspector_666 posted:

If they just want a slideshow, a thumbdrive is the best option anyway.

It really is way easier than updating a fancy live display that's backed by a CMS or something

Irritated Goat
Mar 12, 2005

This post is pathetic.

devmd01 posted:

That's because setting the local admin password via GPO is insecure and deprecated. Use LAPS.

https://support.microsoft.com/en-us/help/2962486/ms14-025-vulnerability-in-group-policy-preferences-could-allow-elevati

I'm gonna suggest it again now that we're not having rampant replication issues.

Siochain
May 24, 2005

"can they get rid of any humans who are fans of shitheads like Kanye West, 50 Cent, or any other piece of crap "artist" who thinks they're all that?

And also get rid of anyone who has posted retarded shit on the internet."


Might be a stupid question, but we've had an issue popup, and I'm not sure how to deal with it/what to use to mitigate in the future.

We have an employee who's likely on the way out the door (company's choice, not their's) - but they haven't officially been let go. Said employee has a laptop and VPN access. Said employee has apparently possibly gotten wind of the fact they might be let go. However, we (as in IT) are not allowed to do anything with said employee's account, as nothing is official yet.

This person has started trying to mess with files that they have access to. Nothing ~hugely~ obvious - just going into excel files and changing formulas, overwriting new data with old, etc. Moving files from places where they share duties with other people, and putting them into folders where the other folks don't have access so they can't do their jobs. Nothing we can't easily recover via VSS or backups, but this is assuming the people who use these files notice.

What can we use to monitor the file server (Windows) stuff lives on to track these events? I realize that would be a lot of logs to parse, but even if we can get something that only looks at specific folders, or only logs access events by specific people, that would be great. Or is there anything in event viewer, etc that might help us verify what's happening?

Bunni-kat
May 25, 2010

Service Desk B-b-bunny...
How can-ca-caaaaan I
help-p-p-p you?

Siochain posted:

Might be a stupid question, but we've had an issue popup, and I'm not sure how to deal with it/what to use to mitigate in the future.

We have an employee who's likely on the way out the door (company's choice, not their's) - but they haven't officially been let go. Said employee has a laptop and VPN access. Said employee has apparently possibly gotten wind of the fact they might be let go. However, we (as in IT) are not allowed to do anything with said employee's account, as nothing is official yet.

This person has started trying to mess with files that they have access to. Nothing ~hugely~ obvious - just going into excel files and changing formulas, overwriting new data with old, etc. Moving files from places where they share duties with other people, and putting them into folders where the other folks don't have access so they can't do their jobs. Nothing we can't easily recover via VSS or backups, but this is assuming the people who use these files notice.

What can we use to monitor the file server (Windows) stuff lives on to track these events? I realize that would be a lot of logs to parse, but even if we can get something that only looks at specific folders, or only logs access events by specific people, that would be great. Or is there anything in event viewer, etc that might help us verify what's happening?

Hit up the infosec thread and hope Lain posts. Logs are part of her specialty.

MC Fruit Stripe
Nov 26, 2002

around and around we go

Avenging_Mikon posted:

I’m in day 2 of 3 in itil v3 training, and people just referenced reddit.
I'm shedding myself of all popularity around here, and it's only going to get worse with this post.

Reddit's fantastic. There are 1 or 2 really strong posts in /r/sysadmin per day. I think people who dislike Reddit are judging it as a whole, which isn't fair. For example, on SA, I only browse a few threads in SH/SC. I don't judge SA by GBS or TFR or any of the 50 or so ironic subforums. Same goes for Reddit.

The Iron Rose
May 12, 2012

:minnie: Cat Army :minnie:

Irritated Goat posted:

Yeah, we've got a lot of it done that way but renaming\setting the password for the local admin user has been oddly flaky.

pspasswd.exe from sysinternals is your friend

LAPS is the better solution if you can get enough buyin

The Fool
Oct 16, 2003


Siochain posted:

Might be a stupid question, but we've had an issue popup, and I'm not sure how to deal with it/what to use to mitigate in the future.

We have an employee who's likely on the way out the door (company's choice, not their's) - but they haven't officially been let go. Said employee has a laptop and VPN access. Said employee has apparently possibly gotten wind of the fact they might be let go. However, we (as in IT) are not allowed to do anything with said employee's account, as nothing is official yet.

This person has started trying to mess with files that they have access to. Nothing ~hugely~ obvious - just going into excel files and changing formulas, overwriting new data with old, etc. Moving files from places where they share duties with other people, and putting them into folders where the other folks don't have access so they can't do their jobs. Nothing we can't easily recover via VSS or backups, but this is assuming the people who use these files notice.

What can we use to monitor the file server (Windows) stuff lives on to track these events? I realize that would be a lot of logs to parse, but even if we can get something that only looks at specific folders, or only logs access events by specific people, that would be great. Or is there anything in event viewer, etc that might help us verify what's happening?

File access logs can be logged to windows events:

https://blogs.technet.microsoft.com/mspfe/2013/08/26/auditing-file-access-on-file-servers/

Infosex thread will likely have other suggestions like AM suggested

E: There is a typo, but I’m leaving it

xzzy
Mar 5, 2009

The secret to reddit is to set the preference to hide downvoted posts and obliterate everything you hate. Or browse it through google using the "site:reddit.com" magic.

There is a lot of good stuff in there, the sheer number of people using it guarantees it, but that also means there's a lot of crap.

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
https://www.youtube.com/watch?v=DOqb_UzJSUQ&hd=1

Peachfart
Jan 21, 2017

RFC2324
Jun 7, 2012

http 418

i like chrome cast for doing slideshows on tv, personally

MC Fruit Stripe
Nov 26, 2002

around and around we go
I can't tell if you guys are just big fans of ironic mashup artists, or earnestly saying to never use reddit, but either way your opinion is wrong.

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else

Siochain posted:

Might be a stupid question, but we've had an issue popup, and I'm not sure how to deal with it/what to use to mitigate in the future.

We have an employee who's likely on the way out the door (company's choice, not their's) - but they haven't officially been let go. Said employee has a laptop and VPN access. Said employee has apparently possibly gotten wind of the fact they might be let go. However, we (as in IT) are not allowed to do anything with said employee's account, as nothing is official yet.

This person has started trying to mess with files that they have access to. Nothing ~hugely~ obvious - just going into excel files and changing formulas, overwriting new data with old, etc. Moving files from places where they share duties with other people, and putting them into folders where the other folks don't have access so they can't do their jobs. Nothing we can't easily recover via VSS or backups, but this is assuming the people who use these files notice.

What can we use to monitor the file server (Windows) stuff lives on to track these events? I realize that would be a lot of logs to parse, but even if we can get something that only looks at specific folders, or only logs access events by specific people, that would be great. Or is there anything in event viewer, etc that might help us verify what's happening?

As mentioned, file access logs can already be looked at. However, it's probably worth addressing the wider surface of the risk. I'd start looking into logging all network access on their accounts in the event this grows beyond just being annoying with some files. Don't let your company turn into Sickening v2.

Bunni-kat
May 25, 2010

Service Desk B-b-bunny...
How can-ca-caaaaan I
help-p-p-p you?

MC Fruit Stripe posted:

I'm shedding myself of all popularity around here, and it's only going to get worse with this post.

Reddit's fantastic. There are 1 or 2 really strong posts in /r/sysadmin per day. I think people who dislike Reddit are judging it as a whole, which isn't fair. For example, on SA, I only browse a few threads in SH/SC. I don't judge SA by GBS or TFR or any of the 50 or so ironic subforums. Same goes for Reddit.

They specifically referenced reddit memes.

And I judge Reddit by its ownership. There are good subreddits but I refuse to give eyeballs and clicks to reddit as a whole.

xzzy
Mar 5, 2009

I can't imagine any manager hearing about an employee loving around with company data or people's ability to do work and not hitting the alarm and pounding the huge "lock this account RIGHT NOW" panic button and immediately terminate the employee.

Logging it and letting them continue? What crazy world do you live in where people are okay with that?

Inspector_666
Oct 7, 2003

benny with the good hair
I find Reddit's formatting unreadable, so unless I end up at a post from a Google search or otherwise direct link, I never use it.

Obsoletely Fabulous
May 6, 2008

Who are you, and why should I care?

MC Fruit Stripe posted:

I'm shedding myself of all popularity around here, and it's only going to get worse with this post.

Reddit's fantastic. There are 1 or 2 really strong posts in /r/sysadmin per day. I think people who dislike Reddit are judging it as a whole, which isn't fair. For example, on SA, I only browse a few threads in SH/SC. I don't judge SA by GBS or TFR or any of the 50 or so ironic subforums. Same goes for Reddit.

The problem is even in the “good” subreddits you still have the unironic references to men’s rights, reverse racism, and all that other bullshit. For example someone arguing that there isn’t racism/sexism in the IT hiring process.

Ugato
Apr 9, 2009

We're not?
And the formatting often leads to those comments floating to the top because there seems to be a lot of that sentiment there. I’ve delved into reddit some just because I’ve been interested in games and other topics that aren’t well represented on SA but I very rapidly run out of patience.

spog
Aug 7, 2004

It's your own bloody fault.

xzzy posted:

I can't imagine any manager hearing about an employee loving around with company data or people's ability to do work and not hitting the alarm and pounding the huge "lock this account RIGHT NOW" panic button and immediately terminate the employee.

Logging it and letting them continue? What crazy world do you live in where people are okay with that?

This.

Personally, I would discover that there was an issue with their account for some highly technical reason that required you to kill all their access while you 'fixed' it.

Peachfart
Jan 21, 2017

Reddit is occasionally useful for obscure topics, but it is a chore to read due to the worst formatting in existance and it suffers from the combo of only popular posts float to the top/the popular posts are usually terrible memes.

Jowj
Dec 25, 2010

My favourite player and idol. His battles with his wrists mirror my own battles with the constant disgust I feel towards my zerg bugs.

Siochain posted:

Might be a stupid question, but we've had an issue popup, and I'm not sure how to deal with it/what to use to mitigate in the future.

We have an employee who's likely on the way out the door (company's choice, not their's) - but they haven't officially been let go. Said employee has a laptop and VPN access. Said employee has apparently possibly gotten wind of the fact they might be let go. However, we (as in IT) are not allowed to do anything with said employee's account, as nothing is official yet.

This person has started trying to mess with files that they have access to. Nothing ~hugely~ obvious - just going into excel files and changing formulas, overwriting new data with old, etc. Moving files from places where they share duties with other people, and putting them into folders where the other folks don't have access so they can't do their jobs. Nothing we can't easily recover via VSS or backups, but this is assuming the people who use these files notice.

What can we use to monitor the file server (Windows) stuff lives on to track these events? I realize that would be a lot of logs to parse, but even if we can get something that only looks at specific folders, or only logs access events by specific people, that would be great. Or is there anything in event viewer, etc that might help us verify what's happening?

I can speak to some of this. Not all of this may fall under your purview depending on the size of your shop, but this is the sort of thing you wanna take seriously.

Tracking Who Did What and Where:
For windows stuff you really wanna look at enabling Access and Audit logs. Depending on your sphere of responsibility looks like this is either easy or a pain in the rear end to set up. Here's a link that talks about it:
https://blogs.technet.microsoft.com/mspfe/2013/08/26/auditing-file-access-on-file-servers/

There will be gotchas specific to your environment I can't speak to, but Advanced Access and Auditing seems to be the best option by a large margin on Windows.

Recovering from Bad Actors:
Have a backup plan. People in this thread can talk to you about implementation better than I can, but if you have logging and everything set up with no recovery you are gonna know who to blame and still have a bad time.

Last thoughts:
Some companies really like the idea of rolling your own FIM. I strongly recommend against this. I inherited a lovely FIM written in C# and I am now the sole dev on it when my team lead left. It sucks. I've written a poo poo load of tests and powershell management scripts to keep it running but it falls massively short of Auditing and Access logging

Some companies already own an EDR product that does FIM stuff. I can't speak to those, but know that these exist and some people swear by them.

Aunt Beth
Feb 24, 2006

Baby, you're ready!
Grimey Drawer

Siochain posted:

What can we use to monitor the file server (Windows) stuff lives on to track these events? I realize that would be a lot of logs to parse, but even if we can get something that only looks at specific folders, or only logs access events by specific people, that would be great. Or is there anything in event viewer, etc that might help us verify what's happening?
Varonis DatAdvantage is FANTASTIC. It costs an arm and a leg but is worth every penny. Their support is out of this world too.

Obsoletely Fabulous
May 6, 2008

Who are you, and why should I care?
Things that aren’t pissing me off: My drat replacement hasn’t listened to a single thing I’ve told him. Not using the correct templates, writing queries directly in the database instead of using the reporting tool, etc. He seems pretty determined to not follow company policy at all but none of this is my problem and I have to keep telling him the most basic things like what the password is for the reports account. Best part is none of this is actually my problem. 8 more days and I’m at the new job.

We were also screen sharing the other day and he has a job hunting site and a few interview question primer websites up. I’m pretty sure offshoring my position is going to bite this company in the rear end hard. Hopefully there is some karmic justice.

dragonshardz
May 2, 2017

Obsoletely Fabulous posted:

The problem is even in the “good” subreddits you still have the unironic references to men’s rights, reverse racism, and all that other bullshit. For example someone arguing that there isn’t racism/sexism in the IT hiring process.

:yikes:

Ham Equity
Apr 16, 2013

i hosted a great goon meet and all i got was this lousy avatar
Grimey Drawer

Aunt Beth posted:

Varonis DatAdvantage is FANTASTIC. It costs an arm and a leg but is worth every penny. Their support is out of this world too.

This. I'm not even the one in charge of this system, but the few times we've used it in the past (like, actually had to query it), it's worked very well. It will also alert based on used behavior.

silicone thrills
Jan 9, 2008

I paint things
I used Varonis at my last job and I miss it so so much.

Aunt Beth
Feb 24, 2006

Baby, you're ready!
Grimey Drawer

Thanatosian posted:

This. I'm not even the one in charge of this system, but the few times we've used it in the past (like, actually had to query it), it's worked very well. It will also alert based on used behavior.
Yeah, they actually have some pattern recognition that they refer to as the "two weeks' notice detector." The software builds a profile of each user based on what they access regularly, and if you deviate wildly outside that it can send alerts to people (or take action, such as disabling accounts). This is useful for cryptoware, as it can alert if an account is suddenly modifying 30,000 files in a share where they usually only touch 6 files a month. It's also useful if someone is trying to throw sand in the gears before they leave, by alerting that they're going places they don't usually go and touching things they don't usually touch.

Myrridinos
Jan 7, 2010
I hate hate hate switchable graphics in laptops.

Siochain
May 24, 2005

"can they get rid of any humans who are fans of shitheads like Kanye West, 50 Cent, or any other piece of crap "artist" who thinks they're all that?

And also get rid of anyone who has posted retarded shit on the internet."


xzzy posted:

I can't imagine any manager hearing about an employee loving around with company data or people's ability to do work and not hitting the alarm and pounding the huge "lock this account RIGHT NOW" panic button and immediately terminate the employee.

Logging it and letting them continue? What crazy world do you live in where people are okay with that?

If they would loving listen to us, yeah, said person's account would be deactivated. As it is, we have full backups, VSS, etc. They aren't the most techy, and lack local admin, plus shares are locked down, so its likely not an issue aside from this. Said person does not have access to any business critical data/systems - they could cause a mess, but nothing we can't fix in a couple of hours. They're more intent on loving over some other employees who have "slighted" them.

I'm going to look into Varonis Datavantage - we've got a budget, and I can justify the use-case to higher ups. I'll try to get a quote on it.

Just trying to prevent drama that I'll be sucked into regardless :/

Aunt Beth
Feb 24, 2006

Baby, you're ready!
Grimey Drawer
Shoutout to their sales process too. Their pre-sales engineers will bend over backwards to help you set up a good POC and do all the hard work producing reports and pretty charts on how insecure your data is that they will help you present to C-levels.

evobatman
Jul 30, 2006

it means nothing, but says everything!
Pillbug

Myrridinos posted:

I hate hate hate switchable graphics in laptops.

Disable it in BIOS/UEFI/drivers/anywhere if possible. It is the devil.

dogstile
May 1, 2012

fucking clocks
how do they work?

Obsoletely Fabulous posted:

The problem is even in the “good” subreddits you still have the unironic references to men’s rights, reverse racism, and all that other bullshit. For example someone arguing that there isn’t racism/sexism in the IT hiring process.

Downvote and move on.

You still post on SA and some of our moderators have been absolutely loving atrocious human beings.

Sefal
Nov 8, 2011
Fun Shoe

Myrridinos posted:

I hate hate hate switchable graphics in laptops.

I hate this so much.

The Macaroni
Dec 20, 2002
...it does nothing.

Sefal posted:

I hate this so much.
I don't mind so much that it's there. I mind that it's so easy for users to trigger, and that there isn't a handy "panic button" to revert to a safe graphics mode.

Irritated Goat
Mar 12, 2005

This post is pathetic.

dogstile posted:

Downvote and move on.

You still post on SA and some of our moderators have been absolutely loving atrocious human beings.

Has SA had some garbage people? Abso-fuckin-lutely. It's the internet. There are ALWAYS garbage people. Does SA let it slide for long? No. Did Lowtax come out and say it's OK for people to use racial slurs? No.

Reddit is a god drat garbage heap. If you sift through long enough, you find good stuff but there's work to be done. I find it to be less work here.

Just a thought. :shrug:

Judge Schnoopy
Nov 2, 2005

dont even TRY it, pal
I never learned how to read Reddit and the million sub-threads for each topic. I enjoy the conversational style of SA where we all contribute and add to the discussion linearly.

Thanks Ants
May 21, 2004

#essereFerrari


Sefal posted:

I hate this so much.

Love to have one bit of embedded content in a webpage kick the whole machine to a dedicated GPU and drain my battery in three hours because it doesn't know how to switch back.

Adbot
ADBOT LOVES YOU

Bob Morales
Aug 18, 2006


Just wear the fucking mask, Bob

I don't care how many people I probably infected with COVID-19 while refusing to wear a mask, my comfort is far more important than the health and safety of everyone around me!

Does this seem weird to anyone?

Good Morning Managers,
We have been growing as a company since 19xx, and what growth it has been. Whether it is in numbers, products, culture or opportunities, and we have been taking this growth in stride. We all hold unique talents or knowledge base that make us strong and allows us to do great things. These same talents and knowledge is what adds value to everything we do. But I ask you; if you were to leave the company and retire today, move out of state, or change employers would you feel you left your team or the company with value to continue to forward progress and growth? Could you step back and say “Team, You Can Do This”? Have you equipped your team and company with all the knowledge, trust and confidence they will need to continue to add and bring value to the company?
These are the questions that as leaders we need to be able to answer on a regular basis. You never know when that day will come and we need to be prepared when it does. So with that, we will begin looking at each department; each area of opportunity to start to develop that succession plan, we need to find that starting point. That starting point begins with you.
Please take some time to review the attached file. It is a list of critical area of leadership, knowledge and support that our company and culture needs to move into the next 30 years of greatness. What I would like for you to do is:
1. Evaluate each position and area
2. Select who you think would fit each role and when
a. Each role should have minimum of one name for each time frame
3. If there is not a person that you feel fits within the time line mark NONE in the box
4. Once complete send back to me (not the HR email address)
After everyone has submitted their matrix we will meet to discuss your thoughts and findings and what the next steps will be. Remember as you are doing this exercise, you may find that there is hidden talent in other departments. Having the right persona in the right role is always the goal.
Please have this back to me by end of day Friday, April 27th.
Thank you,
HR LADY


This spreadsheet (with about 3 more rows of 'managers') accompanied the email



So I'm supposed to offer my 'insight' on all these other jobs that I don't know anything about? Can I put someone in 'READY NOW' if the person currently in the position is completely incompetent?

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply