Educause Security Discussion mailing list archives

Re: privilege escalation software


From: Adam Maynard <AMaynard () CLARKU EDU>
Date: Fri, 26 Jan 2018 13:43:40 +0000

You could do it without additional software.

If you just want to allow users to install software without giving them admin privs, you could whitelist software with 
AppLocker with Windows 10.

If you just want users to authenticate to elevate, you could create a second set of privileged credentials for your 
users. For example you login with your normal user account (let's say "CSmith") - then to do a privileged task, you 
elevate with the second account (let's say "CSmith.s"). That's the tried and true method that windows brought over from 
Linux.


-Adam

From: The EDUCAUSE Security Constituent Group Listserv [mailto:SECURITY () LISTSERV EDUCAUSE EDU] On Behalf Of Chad 
Smith
Sent: Friday, January 26, 2018 08:23
To: SECURITY () LISTSERV EDUCAUSE EDU
Subject: [SECURITY] privilege escalation software

Wayne State College is looking for privilege escalation software so that we can remove our users from the local 
administrators group on workstations.    We aren't looking to remove the control of the PC from our users, but would 
like to force them to be aware when they are elevating a process.   An ideal solution would allow the user to initiate 
an elevation and then be prompted to enter their username/password again, or perhaps enter a code or username/password 
that would expire after a short time.   WSC does not have a 24/7 helpdesk so the approval and delivery of any codes or 
username/password combinations would need to be automated.

Does anyone doing anything like this?  I'm interested to hear what your approaches are and what tools you use.

Thank you,

-Chad

Current thread: