Educause Security Discussion mailing list archives

Re: privilege escalation software


From: "Mr. Ikram Muhammad" <ikram.muhammad () SCRANTON EDU>
Date: Tue, 24 Apr 2018 20:03:55 +0000

We use Viewfinity for endpoint privilege escalation and worked pretty good for us.


Best Regards,

Ikram Muhammad, CISSP, PMP, CCNA Security, CEH, CISM
Information Security Engineer
The University of Scranton
Phone: (570) 941-6514
Email: ikram.muhammad () scranton edu<mailto:ikram.muhammad () scranton edu>
Information Security Offfice Email: infosec () scranton edu<mailto:infosec () scranton edu>
Information Security Office 570-941-4226


From: The EDUCAUSE Security Constituent Group Listserv <SECURITY () LISTSERV EDUCAUSE EDU> On Behalf Of Chad Smith
Sent: Friday, January 26, 2018 8:23 AM
To: SECURITY () LISTSERV EDUCAUSE EDU
Subject: [SECURITY] privilege escalation software

Wayne State College is looking for privilege escalation software so that we can remove our users from the local 
administrators group on workstations.    We aren't looking to remove the control of the PC from our users, but would 
like to force them to be aware when they are elevating a process.   An ideal solution would allow the user to initiate 
an elevation and then be prompted to enter their username/password again, or perhaps enter a code or username/password 
that would expire after a short time.   WSC does not have a 24/7 helpdesk so the approval and delivery of any codes or 
username/password combinations would need to be automated.

Does anyone doing anything like this?  I'm interested to hear what your approaches are and what tools you use.

Thank you,

-Chad

Current thread: