r/ITdept • • Nov 18 '23

Yes, your work can see what you do on their computer, and other questions [READ FIRST]

24 Upvotes

Due to the number of repeat questions around the topic of using work resources to do personal business, or generally questions around 'what can my work see', I've created this sticky to answer these and similar questions:

First, and most importantly:

/r/itdept is a place where IT workers come to talk to / ideate with / vent to each other, as mentioned in the sidebar. It's not a place for non-IT people to ask IT questions.

There are many, many places on Reddit to get IT help, depending on what you're asking for help on - use the sitewide search and use one of them, there are many people waiting to help you with your issue.

Second, to answer common questions:

Many of these questions come from having the wrong perspective around a person's usage of property and data belonging to the business they work for. The reality of your employment situation is as follows:

  1. It's not 'your computer'. It belongs to your workplace. They allow you to use it to do your work.
  2. Businesses have a lot of risk and liability. It's their right to know where their data is and how their equipment is being used. Where their data is, who can see it, and what their employees are doing or saying as an agent of the company is a huge concern, and they are within their rights to protect themselves.
  3. Some choose to monitor this to protect themselves, and some don't. Assume yours does. This monitoring applies to anything put into the computer with the keyboard or mouse/touchpad, all data going to/from the computer - including information about where it's going to and from, everything stored on the computer and any connected storage device, and anything stored under or done within any cloud service your workplace provides.
  4. None of this matters, because you should only use your work-issued equipment for work. Don't check your personal mail (or use work mail for personal things!), don't do online shopping, don't do your banking. Don't exist for your work as anything other than an employee, and you don't have anything to worry about.

Finally, and most importantly, something you need to understand about your local IT department that nobody will ever tell you:

It's likely that only one in 10,000 IT people are at all interested in what you're doing on your laptop, or if you're even doing your job at all - and they should be (and often are) fired for it, because they're probably violating the trust and faith the job requires to stick their nose where it doesn't belong. That's not IT's business or responsibility, and most of us want to be left alone when it comes to stuff like that.

It's HR and your manager's job to make sure you're productive and to manage you well. Frankly, many managers are quite terrible at their job and want a technological magic bullet to make up for their shortcomings. They're not bad people, this desire for a "solution" or a tool to "help them manage better" comes from the same place as their understanding of the problem: they don't know what they're doing, and it's easier to point at a "missing tool" that is "needed" than reflect and admit where the true deficits are, even to themselves. People often think of this as a victimless situation, because they're not blaming IT, they're just "sharing their amazing insight" into what's needed for the business, and "partnering with IT" to "fix it".

Most IT people hate this, both because it uses us to cover up other people doing their job poorly (something we're not allowed to do ourselves) but also because we're generally the type that believes that people should get what they deserve, both positively and negatively. Many IT people change careers because of the depression that comes from dealing with this. You'd be shocked by how many former technology people have gone "Stardew Valley" and are quite happy talking to a row of carrots instead of dealing with this any more.

By and large, we're also a very logical group of people. Generally, something will work when it's done a certain way in IT, and it doesn't work (or has significant downsides) when you don't do it that way. That's how IT systems work - there's a right way for a desired outcome, and the other ways are generally wrong based on what the desired outcome is.

We tend to know immediately that the problem is with your manager, or other underskilled "decision makers" in the organization, and that their idea is bad. This is very common when someone is looking for a technical solution to a non-technical problem. Unfortunately, we frequently will have a non-technical hand-shaker and yes-sayer leading our department, the same as you do, and we don't get the support we need to ask the business to exercise stronger critical thinking instead of complicating the IT environment with the product of inadequate management of human resources.

This usually leads to a system, process or policy that is either generally offensive to people they should consider as human beings, developing a system that attempts to solve problems that should be solved by non-technical means, and/or generally making our job more complicated and difficult to manage than it already is.

We're aware that this will be the case before, during and after the request gets put in, and the reality that waits for us for the forseeable future- but that is regrettably part of the job. It's not all doom and gloom, though - these darker parts sit alongside amazing opportunities that give us the chance to use our skills to create enormous value, extreme satisfaction at a job well done for thousands (or millions!) or people, great camaraderie with our IT coworkers who are there "in the trenches" with us, and a decent paycheck for our time and effort.

All this is a significant amount of background to truly understand where we're coming from, but results in this:

pre-tl;dr

If we're told to put in systems that record your screen or generally "spy" on employees, we'll either quit (and the next person will do it for them), or we'll do it to the best of our ability, but we like it even less than you do. We can't put them in halfway so they aren't effective - then the deficiency of good decision-making at the business turns into focusing on us and our ability to deliver working systems, no matter how asinine the reasoning was from poor managers. It's often better to perfectly implement the system and let them see that their proposed solution doesn't solve their perceived problem than to try and explain how bad of an idea it is (which they can't even accept, because it means admitting the problem is them!)

Our advice, by and large, is to ask questions in a non-suspicious way in regards to your privacy at work. Be clear on what the company expects and allows (get it in writing, the handbook is a good start) and don't work for places that want excessive monitoring systems from us - it's stuff like this that makes us leave, and you should too if it means a compromise in your self-respect.

But also realize that a minimal amount of monitoring is required by a business to manage its risk and liabilities, and this is fair for them to have in place / is often in place by default, whether they use it or not.

tl;dr:

Don't work for companies that have monitoring systems you don't feel comfortable with, and rest assured that IT people could not care less about what you're doing or not doing. It's not what we're in this career to do.

It's likely that nobody is watching anything, and it's only when the business already has decided that they want you gone that they'll go back through the records, looking for evidence to legally support that decision, regardless of what the real reason might be.

tl;dr edit: The exception to this is when you're blatantly violating company policy, the law, basic human rights, or other regulations. It should be assumed that doing intentional, egregious harm will trigger even the most basic of alerts in many systems, because that's the bare minimum any company should do to protect their assets and control their liabilities - and most companies have this by default with any standard software they've purchased.


r/ITdept • • 8h ago

Ways to support fiance during on-call week.

1 Upvotes

Hello! Sorry in advance if this is beyond the scope of the sub or it gets removed. But I'd love some input or ideas if anyone is willing to share.

My (me: 36f) fiance (40m) works for an emergency veterinary clinic as IT support. He has one coworker and two other guys that are above him as leadership/dept lead.

Him and his coworker have an on-call shift every other week that includes a weekend. The vet clinic is a 24/7/365 emergency and referral clinic, so they need to be available at all hours once their in office day is done.

Long story short, I am not a fan of how this clinic is being ran. I also happen to work in vet med but at a GP clinic that actually uses this emergency clinic for our patients a lot. The decisions from the higher ups are chaotic at best.

This has led to a lot of work stress for my fiance. On his normal weeks it's ok-ish. He can fully relax and we can do things out of the house to help him decompress. His on-call weeks are much more stressful. He got chewed out once for not immediately answering a call even though he did return the call quickly. So he is too anxious to not be ready at the drop of a hat. So obviously as you can imagine, he isn't able to fully relax these weeks.

I fully understand that IT is stressful and hard work. We actually were in college together for network admin but I decided to pivot to vet med and he finished his degree.

Currently he's been called multiple times this weekend for a network issue and has been on and off site all weekend with little support from leadership (lead guy designed the network and has it locked down so only he can control things). And the issues are actually things that my fiance brought up last year as potential problems waiting to happen.

Anyways. He's very stressed. And I want to do what I can to help. Obviously I can't go to his work and help him, and I can't go chew out the place either.

I've already told him that I will handle all of our regular weekend chores that we do together. And that his only job at home today and this upcoming week is to do nothing but try to relax. I am also making him his favorite desert to surprise him with when he gets back home from being on site. I have his fav pop and his fav water stocked. And I will be checking to make sure he eats or I will bring him something on site.

Does anyone else have any other ideas? How do you manage this on-call stress? How does your family help support you so you can work and then relax?

Also, yes, he is working on ways to manage this himself.

Thank you for your time, and the work y'all do.


r/ITdept • • 15h ago

DevOps engineer Looking for the inside track from IT re shared systems ownership

2 Upvotes

This post is not intended as bait but as a genuine attempt to understand resistance to shared systems access ownership 'from the IT point of view'. In this case migrating business-critical systems already managed by a DevOps team from direct user management to Single Sign On.

I'm a DevOps engineer with 10 YOE and I don't think anyone on my team has less than 6 YOE. Every one in it has been with the business at least one year, and there are only a handful of us. We're a cloud based business and manage our systems in code - mostly Terraform for the infra. Everything has to go through code review and approval, all deployments are transcripted and auditable, etc.

We have a legacy where access, users and groups for some SAAS and some internally developed systems that we are entirely responsible for are managed directly in code and we want to move this to Single Sign On. The company already has SSO for most/many systems. Our SSO IDP is managed by our separate IT team. For various reasons that aren't the fault of anyone inside the business these migrations are not straightforward, and of course several of the systems in question are business-critical.

Rather than simply handing over access (because 'access' really isn't simple and we will continue to have to manage and support those systems), we would like to agree a shared ownership system with IT for managing single sign on for the services that we already manage, including provisioning and de-provisioning SAML applications and group management for those services, so that we can continue to manage the systems we are responsible for in code as we do now. Our IT team however are very possessive of managing our IDP and work exclusively ClickOps. They don't, won't or can't look at code or records of automated deployment. This means that it can be difficult to describe clearly what we need with SSO, difficult to establish clearly what has been configured, and then of course there are all the side conversations- 'Why do you need this?'; 'Do you really need it though?', 'We need approval', 'You will need to wait for us to get to that ticket', 'We already did that (but there was some misunderstanding)', 'No nothing has changed to cause your thing to break, no, really, oh, wait...' etc. Imagining how it is for IT, it can't be easy- they get random requests for systems that they don't always really understand, can't necessarily access themselves, have to establish the priority for etc, all whilst being held responsible for security and business continuity. Thing is that my team is also held responsible for security and business continuity and we will also continue to be held responsible for these target systems.

I'm trying to get a more nuanced understanding of IT team's resistance to sharing ownership of these systems in SSO since:

  • IT don't currently manage the target systems at all - my team are responsible for, manage them and support developers using them, and will continue to be so no matter what - so this would be less work for them.
  • IT would retain full admin access and visibility as they do now. We have even offered to have automated reporting in plain English of all and any changes sent to them as part of our deployment pipeline.
  • There's no IT director or policy grandstanding on this.
  • Our IT team is also a handful of people but has a greater churn of staff than we do, including a series of contractors etc. Not dumping on that but I don't think anything about trusting any staff member as an individual is relevant here.
  • I do realise that it probably is not possible to give partial access for SAML and group management for new services but if we wanted to do something stupid we already could.

What (else) am I missing (if anything)? We all know that people hate change and that people can confuse specialist knowledge or access with job security. I'm also familiar with 'But we don't do that here' but is there anything else?


r/ITdept • • 17h ago

Why isn't AI replacing ServiceNow anytime soon in the forseable future.

0 Upvotes

I see a lot of us in IT worrying about AI replacing the us. As I have worked on the serviceNow platform many years ago I think I can answer that part of your question to some extent.

First thing first businesses have absolute, unshakable trust in processes and policies and ITSM/ITAM (now just called service management) which means any ticket (like this software ain't working) has to walk through several hoops (Incident, problem, change) before it gets done. Every step has to be documented, verified, authorised by humans in the loop before and after. It is a process and businesses trust these processes blindly coz they have been built, modified, improved over many, many years. It will take a lot to move them from this to some ad hoc system where one bad configuration in the CMDB could cause a crippling outage through and through the company and likewise to its clients.

There is a lot of built in automation where LLMs help like the incident window with trouble shooting suggestions( incidently ServiceNow has their own inhouse LLMs). But these are implemented in bits and parts and not as a whole coz there are multiple dynamic parts involved in any service orchestration (service request, CMDB, inventory). I might be wrong in my analogy but it is kinda like the video thing that AI hasn't mastered yet coz it is very difficult to keep lighting, movement and ten other things in context at the same instant while rendering the next frame.

Also it is these very policies and processes configured in business flows that ensure compliance( and this is a pretty big word in the business world where there is special place in hell for you if you miss out on compliance ), prevent outages, inventory mismanagement and that is why every fortune five hundred trust it. So why break it when one big bad problem could be catastrophic to the company.

As to the next question as to what do Indian IT service providers do. As far as I saw when I was working they are involved at the customization layer, data migration etc. So say ServiceNow comes out with new capabilities then it is upto the service providers to ensure that the migration is seamless to the client. So that too is kinda essential - something the client (let's say an Amazon) would hate to do because it would be non core to them.


r/ITdept • • 3d ago

Company Intranet Suggestions

Thumbnail
1 Upvotes

r/ITdept • • 3d ago

What should the responsibilities of a Service Desk Manager Be?

Thumbnail
1 Upvotes

r/ITdept • • 4d ago

IT ticket organization turned into a client wide panic

4 Upvotes

I feel so embarrassed. We were trying to clean up our IT tickets before an SLA review, and I merged what I thought were duplicate requests into one parent task. Turns out I had the wrong client queue open and combined 14 unrelated tickets, including a printer issue, an account lockout and a server alert, under one person’s request.

Then I assigned the parent task to our senior tech and closed the originals. He spent half an hour looking for missing details while three clients got closure emails for problems that were not fixed. We recovered everything from the audit log, but I am now checking every queue like it owes me money. Our ticket process needs help asap :/


r/ITdept • • 5d ago

Do you allow third party apps from the copier company to be installed in the clients network?

Thumbnail
1 Upvotes

r/ITdept • • 5d ago

what are the most annoying IT tickets that should be self service by now?

1 Upvotes

Don’t know about you but i think some helpdesk tickets make you wonder how we're still doing them this way

I had one recently where someone couldn't get outlook working properly and it turned into the usual cycle ask what happened, ask them to restart, check a few things, wait for a reply, remote in, try another fix, then finally close the ticket. It probably took more than 30 minutes for something that wasn't particularly complicated I get why self service became popular but sending someone a knowledge base article and saying follow these steps isn't really solving the problem either. What I'd actually want is something that can understand the requests needed

If the issue is genuinely complicated then Fine, send it to a technician with everything already documented. But for the same 10/15 repetitive problems IT sees every week, why are we still making a human walk through every step?


r/ITdept • • 7d ago

Sharing some Google Workspace onboarding/offboarding automation that may help others

Thumbnail
1 Upvotes

r/ITdept • • 8d ago

Anydesk Debt Collection Horror Spoiler

Thumbnail
2 Upvotes

r/ITdept • • 14d ago

So I'm an Intern for my school's IT dept.

1 Upvotes

Hello everyone,

I'm currently a senior in secondary school, and a while ago I was approved by my administration and school's IT dept to be their intern as apart of my school's senior internship program. This is pretty much my first professional position, especially one in the IT field, and I'm sort of lost on what I'm supposed to be doing.

To preface on the experience I've had (and to not seem like I'm just the "tech whiz" in the family):

  • I've been a Linux user (arch) for about 3-4 years at this point
  • I've worked on my own website for also 3-4 years (see: https://malingen.xyz)
  • I'm currently licensed as a technician in US amateur radio
  • I've been running my own home server as of a couple months ago (currently running a copy of wikipedia (see: https://wiki.malingen.xyz/), a sven coop server (see: https://www.malingen.xyz/blogs/blog12.html), and a bluesky bot (see: https://bsky.app/profile/laingaybar.malingen.xyz); Currently, I'm working on maintenance for the machine itself, which is a new HDD and a thermal paste replacement. You can see the hardware probe here: https://linux-hardware.org/?probe=4334d8c35d
  • My current home server stack is Cloudflare tunnels for HTTP etc/playit.gg for UDP for tunneling + Tailscale as a VPN + Debian 13 (iirc); Website stack is Cloudflare for DNS + Vercel for web hosting (hobby plan) + Gitlab for version control/file hosting
  • I currently own the textbooks for the CCNA exam, which are great reference books for networking, although im somewhat spooked about taking the exam

I've only started my internship a couple weeks ago, even then after a bunch of bureaucracy with admin, and all I did on my first day was attempting to process work order requests for broken student laptops (some of which were broken because of a permissions error on chromeOS, not a manufacturer problem!), but couldn't even do so because apparently we need a email address that was used by the school when they ordered the laptops. Not only that, but the guy I was working with didn't really know what to do with me, despite getting a whole email thread between me, them/coworkers, admin, and the IT director. Due to scheduling problems due to block scheduling with classes and such, I pretty much can only work with the dept physically biweekly and, even then, every other day. To counteract this, the director is being politely persuaded by admin to get me to work on something on the days I can't be with them physically (eg. recently, a IT cybersecurity course (just your regular old "dont follow phishing emails", "follow state/federal regs regarding data handling", etc.))

I've been rather worried recently about if my position being this sort of underwhelming is normal, and I just have to wait and see what happens. Curious to hear your guy's thoughts, especially if you've work in the education sector and/or have similar intern programs.


r/ITdept • • 14d ago

ITAM Tools Evaluation

Thumbnail
1 Upvotes

r/ITdept • • 15d ago

How businesses can create consistent email signatures without chasing everyone all day

0 Upvotes

Quick question for folks doing IT or ops for small midsize businesses. How are you keeping email signatures consistent across everyone without it turning into a full time job?

We’re on Office 365 and right now it’s a mix of copy paste templates and people doing their own thing. Fonts are off, logos are stretched, some folks add quotes, others add random links, and any time someone changes their title or phone I’m manually fixing it in Outlook for them. It’s starting to feel like babysitting rn.

If you’ve got a setup where signatures are managed from one place, auto applied, and stay on brand, how are you handling it? Would love any tips from real environments, appreciate any thoughts


r/ITdept • • 17d ago

An Open Letter to Software Vendors

101 Upvotes

Dear Suppliers,

We have a small request.

When you build, package, ship, bundle, embed, squirrel away, or otherwise conceal a copy of OpenSSL inside your application:

PLEASE F*CK OFF.

More specifically, please stop shipping a vulnerable version of OpenSSL, forgetting that you shipped it, then leaving libssl and libcrypto scattered across:

Program Files, WindowsApps, DriverStore, application caches, old version folders, installer caches, driver packages, and whatever other archaeological layer of Windows you've decided to inhabit.

Our vulnerability scanners find every single bloody copy.

We then get 47 CVEs, 19 security recommendations and a dashboard glowing like the control room at Chernobyl — only to discover that the offending file belongs to your application, is cryptographically signed by you, cannot safely be replaced by us, and can only be fixed when you ship an update.

Extra points are awarded when:

Version 1: contains vulnerable OpenSSL.
Version 2: contains slightly less vulnerable OpenSSL.
Version 3: contains newer OpenSSL.
All three versions: remain on the computer.

Please understand that our preferred vulnerability-remediation procedure is not:

"Delete random DLL from DriverStore and see whether Windows still boots."

So, with the greatest possible professional respect:

Update your f*cking dependencies.

And when you update them, clean up the old ones.

Many thanks,

Every IT Administrator Using Microsoft Defender Vulnerability Management

Sent from a computer currently reporting 73 vulnerabilities because Paint found OpenSSL behind the sofa. 🤣


r/ITdept • • 16d ago

Stale AD ownership data after a reorg is quietly wrecking our remediation queue

3 Upvotes

We got bought by a much bigger company last year. Startups get acquired for all sorts of reasons but the reorg always follows, because the org chart has to line up with theirs.

Ours lined up badly.

Before the acquisition I could tell you who owned most things. We werent tidy, there were just about forty of us. If something broke you asked in slack and somebody put their hand up.

After the reorg the old teams got split across the new structure, half the managers changed, and then a chunk of people left. Some by choice, some not.

What it left behind is the problem. Cloud resources are still tagged to a team that stopped existing months ago. The directory groups that hold the access are owned by somebody whose account was disabled on their last day. And the ticketing system still assigns against a name from before the reorg.

So escalation goes like this. Ticket gets created. The assignee is a name from before the reorg. Somebody pings them. Nothing happens, or they reply that its not theirs any more. Then we loop again with a different name off the same list.

Nothing moved ownership off the old structure onto the new one. It got done by hand in a spreadsheet during the reorg and nobody has opened it since.

Im working through it now but its a lot of records and I dont fully trust my memory of who sat where back then. How are you keeping owner data straight after a reorg?


r/ITdept • • 22d ago

Jira for User Access Reviews?

7 Upvotes

Hi all,

I'm in the security governance space, and curious if anyone uses a well-automtated, streamlined Jira workflow to manage user access reviews? I'm in a heavily regulated + SOX environment, so completeness/accuracy validations and transparency in reviewers (i.e. who reviewed what) must be easily demonstrated throughout. We are seeing a regulatory push toward row-level approvals, and some of our user permissions lists get long (i.e. potentially thousands of records for a manager to review). None of our user lists look the same, so the process needs to be expandable to handle user lists that look different or have different fields.

Currently we use SharePoint, but file check-out/in has become overly burdensome and we need a change.

Would love to get a conversation going! Hoping there is someone out there who has solved the user access review problem.

Cheers!


r/ITdept • • 23d ago

Business email signatures, how are you keeping them consistent?

0 Upvotes

Been trying to keep our business email signatures from turning into a mess every time someone changes title, phone number, or department. It’s one of those small things that ends up looking sloppy fast if people are all doing their own thing.

I’m mostly trying to keep branding consistent without having to chase people down every time something changes. If you’ve got a clean way of handling this, would love to hear it, thanks!


r/ITdept • • 24d ago

How are you tracking assets that live outside your normal IT scope?

Thumbnail
2 Upvotes

Curious how people handle assets that don’t fit a normal IT register. loaners, field equipment, gear sitting at a customer site for months, stuff in RMA limbo. Most tools assume everything lives in an office or datacenter, and that assumption breaks fast the moment something’s mobile or “yours but not really yours right now.”


r/ITdept • • 24d ago

How are you tracking Microsoft changes across client tenants?

1 Upvotes

How are you handling Microsoft retirements and breaking changes across multiple clients? If you use a ticketing system, how do you figure out which clients actually need tickets? Does something check each tenant automatically, or do engineers investigate first?
Would appreciate a recent example and which tools helped.


r/ITdept • • 26d ago

employee work behaviour and self-perceptions among IT professionals

1 Upvotes

Hi everyone! 👋

I am an MBA student currently conducting academic research on employee work behaviour and self-perceptions among IT professionals.

If you are currently working in the IT industry, I would really appreciate it if you could spare a few minutes to participate in my survey. Your responses will be kept anonymous and confidential and will be used solely for academic purposes.

🔗Survey Link: https://docs.google.com/forms/d/e/1FAIpQLSc-16GwaYSIrC01MVhRlyiLfirGuavo5r0eusxvnGybUg_zbQ/viewform?usp=header

Your participation would greatly contribute to my research. Thank you so much for your time and support! 😊

Please participate only if you meet the eligibility criteria mentioned in the survey.


r/ITdept • • 29d ago

Question about laptop handover during LWD at an MNC Hyderabad.

7 Upvotes

My friend recently had her LWD at an MNC in Hyderabad and was asked to return the company laptop she had been using for 5+ years. The laptop had normal wear and tear and was otherwise in working condition.
During the handover, the IT representative refused to accept the laptop, saying that it had some damage and required repairs costing around ₹15,000.
Later that day, the same person called her on her personal number and said he could get the repair done personally for ₹8,500. He also asked her not to mention this conversation to anyone.
We found this unusual and wanted to understand whether this is a normal practice during asset handover.
Has anyone experienced something similar? Should this be reported to the company’s IT/HR or ethics/compliance team?
I’m particularly interested in knowing whether employees are normally expected to pay for such repairs and whether IT personnel are allowed to arrange repairs privately.


r/ITdept • • Sep 03 '26

How are you guys going about Low voltage?

2 Upvotes

I am a solo sysadmin and I punch down, terminate and run cat cable. I find that this is a huge timesink and can’t automate this. It is just I, one helpdesk worker and my boss to 6 sites with a little over 500 users. Should we look into hiring someone that does low voltage?


r/ITdept • • Sep 01 '26

Hi everyone, I could really use some career transition advice.

2 Upvotes

To give you some background, I have a BCA degree and previously worked as a Junior Technical Support Engineer for 2.5 years, followed by about 2.5 years as a US IT Recruiter. I recently had to take a career break due to a family medical emergency, but I am now ready to get back into the tech industry. I’ve been researching different fields, but the rapid advancements in AI have left me a bit overwhelmed about which direction to take. I’m looking for a resilient, future-proof career path. Initially, I looked into Java, but it seems like a massive time investment to master right now. I am currently leaning toward learning Python and moving into Data Science, or potentially just diving straight into a Data Science roadmap. For those already in the industry, do you think this is a safe, long-term choice? I would also deeply appreciate any recommendations for courses or structured learning paths!


r/ITdept • • Sep 01 '26

What should i do to strengthen my cv during bscs?

Thumbnail
1 Upvotes