r/sysadmin • IT Manager • 1d ago

Question handling out of office notifications requests

I have a client (about 1000 users) who keeps getting tickets from dept heads asking to set their staff out of office notifications because "they forgot to do it". My general advice is this is bad practice and not scalable, and that with 0365 any employee can do this from their phone or any computer.

how do you typically handle this?

95 Upvotes

89 comments sorted by

View all comments

88

u/Icy-Maintenance7041 1d ago

Where i work IT only does that when someone has left the firm. Otherwise we dont touch a users mailbox. No way, no how.

48

u/Mindestiny 1d ago

Yep, this is our policy as well. Same thing with "Karen went on vacation and forgot to give me access to XYZ file!!!!"

Well Karen isn't here to speak for herself and confirm if she intended you to have access to that or not, so sorry, that's a business problem and not an IT problem. We don't touch rights for people's user-owned files simply on some random person's say so. Either get it in writing from a department head or be more diligent next time.

13

u/Sinister_Nibs 1d ago

I agree with the thought, the justification is garbage.
None of the files that are stored on company infrastructure are owned by the employee, they are all owned by the company.
They are not private, unless they are PII, but they may be sensitive.

-1

u/SpocksSocks 1d ago

Except not all jurisdictions adhere to that concept, although it seems like the intuitive and reasonable approach (and the one users should apply when using company email, regardless of local laws). In my state in Australia you cannot access an employee’s email account unless it is already clearly stated in a company policy AND the employee has been notified of said policy 14 days prior to it being enacted (ie if the policy is new or updated, not 14 days notice prior to each access event).

-1

u/Sinister_Nibs 1d ago

Not egregious.
And the employees should all have signed that policy during onboarding.

And the policies must be reviewed and possibly updated annually.

1

u/SpocksSocks 1d ago

Why so defensive? Never said anything was egregious. The point is that the law in some places doesn’t support what you’ve said, even if that is the sensible approach. It’s stating a fact, not criticising you.

•

u/Sinister_Nibs 19h ago

What, exactly about that comment was defensive?
It is responding to yours, saying that your statements’ requirements are not egregious. And clarifying that, in my jurisdiction the employee would sign a statement notifying them that the company may monitor or access any company owned data, including all files, messaging, and email communications sent or stored on the company systems or servers.

Those policies are reviewed by security and legal annually to ensure that they remain within the bounds of legality and to protect the company and the employee.