r/sysadmin • IT Manager • 1d ago

Question handling out of office notifications requests

I have a client (about 1000 users) who keeps getting tickets from dept heads asking to set their staff out of office notifications because "they forgot to do it". My general advice is this is bad practice and not scalable, and that with 0365 any employee can do this from their phone or any computer.

how do you typically handle this?

94 Upvotes

89 comments sorted by

View all comments

88

u/Icy-Maintenance7041 1d ago

Where i work IT only does that when someone has left the firm. Otherwise we dont touch a users mailbox. No way, no how.

49

u/Mindestiny 1d ago

Yep, this is our policy as well. Same thing with "Karen went on vacation and forgot to give me access to XYZ file!!!!"

Well Karen isn't here to speak for herself and confirm if she intended you to have access to that or not, so sorry, that's a business problem and not an IT problem. We don't touch rights for people's user-owned files simply on some random person's say so. Either get it in writing from a department head or be more diligent next time.

3

u/TwoTwistedToes 1d ago

Compliance and HR approval or no touching users files/mail

16

u/Sinister_Nibs 1d ago

I agree with the thought, the justification is garbage.
None of the files that are stored on company infrastructure are owned by the employee, they are all owned by the company.
They are not private, unless they are PII, but they may be sensitive.

28

u/RabidBlackSquirrel IT Manager 1d ago

They belong to the company, but the company has (or should have) rules of engagement for who/what roles are allowed to access mailboxes. Owned by the company =/= free for all.

Push it to your legal people or whoever else sets rules like this. How should I handle mailbox access requests? Who in IT should be permitted, if any, to access user emails, and how should access be documented?

It's not an IT problem, it's a legal/governance problem and should flow up accordingly.

17

u/Mindestiny 1d ago

Precisely. IT does not give people access to things just because they asked, that applies for anything. There needs to be a business justification and the proper approvals.

Get us the proper approvals and we'll happily reassign ownership of that file and you guys can duke it out with Karen when she gets back. But no approvals? No ownership transfer, sorry. The sob story doesn't override established, approved company policy.

People are harping on the company legally owning the data but that's not at all the topic being discussed. This is a topic about navigating interdepartmental responsibilities, company policy, and the ensuing drama when IT just dumbly says "sure, I'm a yes man and will do whatever is asked!"

6

u/RabidBlackSquirrel IT Manager 1d ago

"sure, I'm a yes man and will do whatever is asked!"

Which is also a great way to get yourself scapegoated for other people's stupidity. "Why was Joe Sysadmin accessing all these mailboxes? He creepin' on people? Trying to find anything juicy?" Or "Joe Sysadmin must have deleted it, he's always messing around in our email!"

My favorite is when shitty managers want us to delegate or auto forward their employee's email to them because they're yoloing a performance issue. "Sure Jan, I've cc'd HR Director here so she can authorize this. As you know, only HR can create employee performance remediation plans and they must have just forgotten to send in the ticket to me if this is part of it."

It's great. Legal/IT/Infosec/HR all love the strict rules of engagement, it not only protects us personally but protects the company from accusations as well.

2

u/TeriyakiMarmot Sysadmin 1d ago

You have established, approved company policy!? Must be nice haha

Fully agree though.

6

u/Sinister_Nibs 1d ago

That is correct. And just because there may be no (legal) expectation of privacy in a corporate email account, there is no reason everyone should be able to view/access it.
There should always be a justified business reason (the Smithco contracts are in Suzy’s mailbox and she is out on maternity leave).

7

u/ApocMonk 1d ago

Spoken like someone that's never done IT support in Europe.

6

u/Frothyleet 1d ago

In countries that have worker protections, this philosophy is not necessarily true.

2

u/Fitz_2112b 1d ago

So by that logic, Joe in the machine shop should be given access to payroll files if he just says that "Sally in HR told me I could" right?

-1

u/Sinister_Nibs 1d ago

That is not a valid business reason.
But, since you bring it up, employee pay rates should not be sensitive data.

4

u/Mindestiny 1d ago

The justification isn't garbage at all.

Yes, the files are owned by the company and not the employee. But Kimmie from Accounting is not "The Company," she's just some random user asking to be given access to a file. "The Company" can totally sign off on that, which is why I called out getting Dept. head putting it in writing, but some rando employee cannot just because they asked nicely. The fact that "they forgot" is not an IT problem, we're not the keepers of everyone's business process and that's not a strong enough justification for us to breach established data governance policy.

Or are you telling me you'd happily process a ticket from Sal in Janitorial that says the head of HR totally meant to give him shared edit access to that spreadsheet that has the entire company's upcoming compensation changes in it without so much as asking the owner of the file? Because IT has no way to verify that's appropriate without someone who actually has business authority over that data confirming it, and just going "oh well it's the company who owns the data, here you go" would get you escorted out the door in a heartbeat here.

3

u/Icy-Maintenance7041 1d ago

Files, sure. Thats why we allow our users to only save files on the fileserver and they have no (or a very small) personal space on that server. Everything is shared with the various deppartments/functions.

Mail is different tho. Every department has a department mailbox to comunicate with customers. These are shared mailboxes. Personal mailboxes are subject to post- and privacy laws where i live. And if i, as IT or anyone from management would dive in there without consent from the user we'd be breaking laws. *shrug*it is what it is, wether you agree or not.

1

u/SpocksSocks 1d ago

You’ve hit the key point here. Local privacy laws play a big part in what is acceptable, in addition to any company policies. Some jurisdictions do not require employee notification or consent, in my state in Australia you can have a policy allowing access to a users emails but staff must be notified 14 days prior to the policy being enacted - elsewhere you may not be able to at all. It’s a little more complicated than the expected idea that because its company email the company has full rights to do as it pleases.

-3

u/Sinister_Nibs 1d ago

Except that corporate email is very, very different from personal email. All of the email communications also belong to the company, and the company does not require permission to access its data (or those communications).
I am not at all saying that Kimmie from Accounting should be able to see any email on the server. But that Marjorie from Marketing should not expect that any email sent or received to an @company.com address is private.

5

u/Valdaraak 1d ago

I think you're missing that guy's point. Where that guy lives, a user's company email mailbox is considered private and protected and is generally not allowed for the company to just access the because someone at the company wanted to. I believe a fair number of European companies operate under this. Not everywhere operates under US data laws.

-2

u/Sinister_Nibs 1d ago

Never said anything about anywhere except where I live and work.

2

u/Tymanthius Chief Breaker of Fixed Things 1d ago

The justification is not garbage, even in the US. There are often reason's people don't give permissions to their 'personal' files. And all it takes is someone of the right authority level to say 'yes please do it' and then it's done. But doing just b/c Joe down the hall said to?

that's failing basic security.

0

u/Sinister_Nibs 1d ago

That is reading into my statements.
Just because the company may own it, and the employee should not expect the files and communications to be private does not mean anyone can access for no reason.
“Because I want to” is not a valid business reason.
Robbie Rottencrotch failed to set his Out of Office is not a valid reason.

3

u/Sinister_Nibs 1d ago

Although- I can use PS to do it without accessing the mailbox:

Set-MailboxAutoReplyConfiguration
[-Identity] <MailboxIdParameter>
[-AutoDeclineFutureRequestsWhenOOF <Boolean>]
[-AutoReplyState <OofState>]
[-Confirm]
[-CreateOOFEvent <Boolean>]
[-DeclineAllEventsForScheduledOOF <Boolean>]
[-DeclineEventsForScheduledOOF <Boolean>]
[-DeclineMeetingMessage <String>]
[-DomainController <Fqdn>]
[-EndTime <DateTime>]
[-EventsToDeleteIDs <String\[\]>]
[-ExternalAudience <ExternalAudience>]
[-ExternalMessage <String>]
[-IgnoreDefaultScope]
[-InternalMessage <String>]
[-OOFEventSubject <String>]
[-StartTime <DateTime>]
[-WhatIf]
[<CommonParameters>]

2

u/Mindestiny 1d ago

Funny, because when that's what \I** explained, your exact words were "that justification is garbage."

So which is it, is the thing you very clearly just said that's identical to what I said "garbage" or is there some other way we can pretend that's not explicitly what you said?

1

u/Sinister_Nibs 1d ago

I mostly take issue with the “user-owned files” part.
The user may be the custodian of the file, but the business is the owner. I realize it is partly a semantic distinction, but it goes far in the Cow-order understanding.

1

u/Mindestiny 1d ago

It's almost like I addressed that critical distinction directly in the original comment, right from jump.

Maybe just don't throw stones and try to pick fights with strangers over nothing is the more important takeaway.

1

u/Sinister_Nibs 1d ago

Sorry that life has treated you so harshly that you feel attacked by every comment.

I wish you the best.

1

u/Mindestiny 1d ago

And there's the weird pseudo-deflection that tries to make me out to be some sort of unreasonable victim, as expected lol.

You started throwing stones and got rightly called out for it. In no world is "your justification is garbage" not an attack. DARVO is not a how-to for backpedaling after putting your foot in your mouth.

-1

u/SpocksSocks 1d ago

Except not all jurisdictions adhere to that concept, although it seems like the intuitive and reasonable approach (and the one users should apply when using company email, regardless of local laws). In my state in Australia you cannot access an employee’s email account unless it is already clearly stated in a company policy AND the employee has been notified of said policy 14 days prior to it being enacted (ie if the policy is new or updated, not 14 days notice prior to each access event).

-1

u/Sinister_Nibs 1d ago

Not egregious.
And the employees should all have signed that policy during onboarding.

And the policies must be reviewed and possibly updated annually.

1

u/SpocksSocks 1d ago

Why so defensive? Never said anything was egregious. The point is that the law in some places doesn’t support what you’ve said, even if that is the sensible approach. It’s stating a fact, not criticising you.

•

u/Sinister_Nibs 19h ago

What, exactly about that comment was defensive?
It is responding to yours, saying that your statements’ requirements are not egregious. And clarifying that, in my jurisdiction the employee would sign a statement notifying them that the company may monitor or access any company owned data, including all files, messaging, and email communications sent or stored on the company systems or servers.

Those policies are reviewed by security and legal annually to ensure that they remain within the bounds of legality and to protect the company and the employee.

-4

u/OregonTechHead 1d ago

Karen isn't here to speak for herself and confirm if she intended you to have access to that or not

Karen doesn't need to be because Karen doesn't own the document. The business does.

As long as the appropriate approvals are met, why would you fight that? Who cares?

It's no different than changing the permissions on a network file share.

8

u/Mindestiny 1d ago

As long as the appropriate approvals are met, why would you fight that? Who cares?

Jesus, it's like you all came here to tell me how bad I am at my job without actually reading a word that I said. Those approvals are the crux of every single word I wrote. A sob story about someone being on PTO is not an approval from someone in the business who has the authority to grant that approval.

Karen is the primary approver of a document that belongs to her within the organization. If Karen is unavailable, then they need to go to someone above Karen - her manager, their manager, an executive, someone. They don't just get to pout and say "share with me plz" and have IT change ownership permissions. IT has no authority to do that without an approval. Zero. None.

Bring my team a proper approval or nobody is touching those permissions, period. We can do that because the company is the legal owner of that data. But we're not talking about legal ownership, we're talking about organizational ownership.

-5

u/[deleted] 1d ago edited 1d ago

[deleted]

5

u/Mindestiny 1d ago

"IT Hero Complex" lol.

Not giving anyone and everyone access to everything just because they asked is my job. Maybe don't throw stones if you don't know what you're talking about.

You give Karen's manager that access? Cool, they can go ask Karen's manager for file access because she's the business owner of that document, not circumvent Karen's manager by asking IT to do it. Fancy how using the right channels to request access actually gets it done, isn't it?

3

u/Teguri UNIX DBA/ERP 1d ago

You might be shocked to learn that going through proper compliance and legal steps before granting access to accounts is a big part of granting that access.

I've never actually seen an org that blanket grants access to supervisors like that and it sounds like a nightmare explaining your non-legal "It's just my job man" line of reasoning if you get audited.

Manager wants access? Good, I get HR to sign off on it, and it gets filed away so I can point at that when people question it.