Summary
As part of our ongoing Privileged Access Management (PAM) efforts, we are implementing changes to remove local admin access across the university system. The process will be executed in phases. Each phase will be communicated to team leads, and approvals will be obtained through the Change Advisory Board (CAB). This article explains a workaround for situations where this removal causes a work stop situation.
PAM Removal Project Overview
Action: Endpoint Engineering team removes Local Administrator user accounts from devices in each area as requested.
Method: Current users in “Administrators” group on a device are replaced with a common set of Administrators that include the Help Desk and Desktop Support Groups that are available in both Active Directory and Entra ID. The LAPS Administrator user is also included in this group.
Result: All other Local Administrators are removed from the device. If an exception is granted and remediation policy is applied to the device, there will be manual intervention required to add Local Administrator user account(s) back to the device.
Standard Remediation Process
The official standard process for remediation remains unchanged. If a user requires privileged access, they request it through the Privileged Access Management Service found here: https://td.usnh.edu/TDClient/60/Portal/Requests/ServiceDet?ID=600 . If the user is not in a true work stop situation, then this is the process they should use.
The user goes through training, signs an agreement with approval from their supervisor or manager, then submits their request for Cybersecurity review. Full instructions and access to the required materials are in the Privileged Access Management Service description.
Backout Workaround – FOR WORK STOP ONLY
We have concerns surrounding the removal of Admin access. This is a case of, “We don’t know what we don’t know”. To minimize disruptions during this transition, we have developed a backout plan as a workaround to quickly restore access for individuals in work stop situations while they go through approvals for a more permanent solution.
Backout Model (Workaround): In exceptional cases where unexpected requirements arise, we have created a backout model to expedite the restoration of admin privileges. This model aims to limit any impact to critical services.
If a customer reports that they are unable to work without the local administrator access that was removed through PAM enrollment, then Client Services may use this process as a workaround while their Cybersecurity Exception is being evaluated. After the evaluation is complete, the device configuration may change again based on the results of the evaluation – this may necessitate a revisit...
Cause: After a device has been added to the PAM removal group, it will have policy to keep any non-sanctioned Local Administrator user accounts off the device. Therefore, if the user requires local admin access to perform their work, the device must be added to an exception group and any Local Administrator user accounts manually added back onto the device.
Note: Each situation will be unique. Before you begin, in consultation with the user, try to determine what local administrator user accounts might be needed on the machine.
Steps for Backout Workaround
Step 1 – The user must request a Cybersecurity Exception to have a Local Administrator added back to the device. The Cybersecurity Exception form is found here: https://td.usnh.edu/TDClient/60/Portal/Requests/ServiceDet?ID=545
Step 2 – Open a separate internal service request ticket to the Endpoint Engineering team. Request to have the device added to the exception group to allow the addition of other Local Administrator user accounts. In the ticket you must provide:
- The ticket number of the user’s Cybersecurity Exception request from Step 1.
- The device name.
Step 3 – Once Endpoint Engineering tells you that the device has been added to the exception group, then you can add the Local Administrator user account(s) back to the device.
Need additional help?
Please reach out to Tim Hatfield's DM Endpoint Engineering group if you have questions about this process.