Local Computer Administrative Privileges - BeyondTrust
In order to enhance EIU’s cyber security efforts, ITS is in the process of removing individual users as administrators on their local computers. This will remove users’ ability to install new programs/drivers, but also prevent users from accidentally installing malware and other harmful software.
Just last year, 82 percent of all cyber incidents started with a human element, which is why EIU’s cyber security insurance is requiring us to remove local administrators. When a user is not a local admin, it not only protects the University, but it also protects our users from being part of an unwitting start of a cyber incident.
We will be using an application called BeyondTrust to make this a smooth transition. The program will allow users to install applications that have been approved by ITS. If you need an application installed that is not already approved, you can call the ITS Help Desk at (217)581-4357. ITS will evaluate the application to ensure it is free from malware and that the university is legally licensed to run the software. This review process will be done as promptly as possible, with most being approved within 3 business days.
Over the next few months, IT will be working with each departmental leader/chair to find the best time to deploy this change in your area. This process will be done on a rolling basis rather than removing all users at once.
We understand this is a significant change in process and we will do our best to make this technology change as smooth as possible. We’ve included a FAQ section on this page to address many common concerns about this deployment. If you have any additional questions or concerns, please contact us by emailing support@eiu.edu.
Thank you once again for your commitment to cyber security. Together, we can continue to keep our campus community and its data safe.
Frequently Asked Questions
Why is EIU removing local administrative rights from users?
First, it’s a requirement to for EIU to keep cyber security insurance. Second, it will have real positive impact on the universities security posture. Removing local admins gives EIU additional protection to keep our systems and data safe against attack.
Has EIU tested removing local administrative rights?
Yes, we have been testing with certain groups on campus for many months, including in IT. With BeyondTrust we have found it to have little impact on our user’s productivity.
What does it mean to remove me as a local administrator?
This will prevent a user from installing unauthorized applications, install driver, install printers, or change security configuration. Beyond Trust helps prevent a user from accidently installing malware and ransomware. It will also prevent many harmful email attachments from negatively impacting our systems.
Will IT need to come to my machine to do something or will this be done virtually?
No, all of this work will be done via remote administration.
Do I have to be present for this to happen?
No, the policies will push in the background on the day of deployment.
Is this only for laptops?
This is for both desktop and laptops.
Is this for both Mac and Windows devices?
Yes, this policy change impacts both Mac and Windows devices.
Will I get to choose my time or will ITS and my director/Chair assign a time?
IT will work with your leadership to set the deployment date. We will communicate this date with the users so we are ready to troubleshoot quickly if any issues arise.
What changes will I notice on my machine after this is complete?
Our goal is that very little is changed in your day to day work. When you need to install a brand new program it will need to be reviewed.
Can you give me more details about the review process?
ITS will evaluate the application to ensure it is free from malware and that the university is legally licensed to run the software. You might be asked for follow up questions to help us in the review.
Where is a list of already approved applications that I can review?
The list is different for each department/area and is built from what is currently installed on your computer. Once we have deployed the solution to your area we will be able to provide a list going forward, but know anything currently installed should continue to work.
Will this block my ability to remote into my computer?
Yes. In order to continue to remote into your computer you will need to call the Help Desk at 581-HELP. Remote desktop applies to Windows computers only.
How will I know if the change has been made?
You will see a small orange icon in your taskbar.
Does this replace malware protection or antivirus?
No, it is another tool that prevents unauthorized software from being installed.
I am on a Mac. They don’t get viruses, right?
Apple computers are vulnerable to malware just like Windows.
Does this track what I do with software or what website I go to?
No, this product does not track what you do or what websites you visit.
How do I request new software?
You can use this form.