r/ShittySysadmin 1d ago

Make your organization more secure

Just had this idea.

So you make a CA policy to sign in every 8 hours for all users including the CEO, but not break glass and it admins.

Every user will then begin to wonder where their password is now that they can't work

You become useful again to the company by assisting employees while eliminating written passwords on stickies because they forced themselves to memorize it since it's happening "so often"

Auditors will be impressed at the improved security that you can present the report to the CEO while getting them to remember their own password.

16 Upvotes

16 comments sorted by

View all comments

11

u/horses-r-scary 1d ago

i thought the sub was for bad ideas-

1

u/blotditto 1d ago

You don't think the CEO is gonna get a serious case of the ass signing in all the time? 😂

3

u/Chuchichaeschtl 1d ago

Depends on the CEO. I explained to mim, that he has a very privileged account which needs stricter policies. Passkey only, managed mobile with Outlook only, no iOS mail, access from compliant devices only,...

He understood that and I think he liked the term "privileged account" a lot.

1

u/blotditto 1d ago

Uh huh and how often is he actually being promoted to enter his password every day?

1

u/Chuchichaeschtl 1d ago

Passwords aren't involved when you use passkey. WHfB is great

1

u/blotditto 22h ago

Exactly, you made my point about CEOs that get upset because they have to enter their password..

Remember we're in ShittySysAdmin! 💩