Skip to end of metadata
Go to start of metadata

You are viewing an old version of this page. View the current version.

Compare with Current View Page History

« Previous Version 11 Next »

Unknown macro: {float}
Error formatting macro: include: java.lang.IllegalArgumentException: No link could be created for 'exchange2010:Snippet - Disclaimer'.

Remote Vendor Access

As a support provider, you may need to work with outside vendors to enable them to support your systems. To maintain system security while allowing vendors to perform authorized maintenance (especially on Windows systems), consider these recommendations.

Unknown macro: {div2}
Unknown macro: {div3}

Always Use AD

Create vendor accounts in AD, not on the local system. This will allow for more effective management and monitoring, as well as provide RDP access through the VPN. Be sure to create account names that won't cause collisions with UTLNs (e.g. "vendorname_systemname_vendor")

Unknown macro: {div3}

Group Vendor Accounts Together

Group third-party (including vendor) accounts together in one AD group so that you can easily run reports on them (expiration, usage, etc.)

Unknown macro: {div3}
Unknown macro: {float}

Restrict Vendor Logon Rights

Restrict logon access in AD to only those machines that the vendor supports. (User account->Properties->Accounts tab->Log On To...)


Unknown macro: {div3}

Disable Vendor Accounts Until Needed

Create vendor accounts and assign the appropriate rights, but disable them in AD until and unless they are needed. This will prevent vendor access without your authorization or knowledge.

Unknown macro: {div3}

Use New Passwords for Each Maintenance Cycle

When you enable an account, set a new password and share it with the vendor. This will prevent e.g. ex-employees of the vendor from logging on with credentials they may have saved while on the job. This concern is especially relevant for systems with regulated or sensitive data.

Unknown macro: {div3}

Report on Account Activity

Use AD to report on vendor account usage and examine any unexpected activity.

Unknown macro: {div3}

Disable and Remove Old Vendor Accounts

Disable and remove old vendor accounts that are no longer needed. This will prevent vendors from logging in when they shouldn't, and will prevent employees of the vendor from logging in without authorization.

  • No labels