Here on the campus I work it's been standard for years for the full time staff and faculty to have admin privileges on their Windows and Mac systems. I've opposed this over the 18 years I've been employed but it falls on deaf ears.
After some recent investigation I noticed how easy it is for someone on a Mac to get root access with their admin account from the terminal and then cd into /Volumes and access smb file shares for another user on the system. This, then, more or less disguises anything that user does through the root account as if it was the user who owned that smb file share.
This is a huge security hole. There is such a tough mindset here that staff and faculty must have admin privileges that I don't know that this would even be an argument to remove them but if I can find a way to block root access from the admin accounts then that might be doable.
Does anyone have experience with this that they could share?
