Skip to main content
Question

Log Admin use on clients

  • October 4, 2019
  • 4 replies
  • 12 views

Forum|alt.badge.img+10

Our Mac users are admins. But my feeling is that actually very few are using it.

So my question is, if it Is possible somehow to see in logs etc, when a user have been prompted for admin password when they are logged in

If there are users that have not been using their admin preveliges it for long time, why then not just block admin access for those, to minimize risk on clients

4 replies

Forum|alt.badge.img+9
  • New Contributor
  • October 4, 2019

Would it not be simpler to set all users to standard and use a script in Self Service to promote them to admin temporarily when the access is needed? If you've got a large population of users who do not need constant admin permissions, this seems more secure.


Forum|alt.badge.img+10
  • Author
  • Contributor
  • October 4, 2019

Yes but this the reqq


Forum|alt.badge.img+10
  • Author
  • Contributor
  • October 4, 2019

Sorry - then there Will have to be a lot of decision made and lots of talk, communications to users - which I would like not to start with until I know how big the need is.


Forum|alt.badge.img+31
  • Honored Contributor
  • October 6, 2019

You could use a loginhook policy to test if that user is in the admin group and then log it if that is what your Org is requiring you to do