Jump to content
MrRat

MSP Accounts Plugin - Free

Recommended Posts

Plugin Updated to version 2.16.2.22

link in first post downloads the most current version

 

Fixes

* issues with domain Service Account fixed - it now uses the same code as regular users

* now using thread pooling - should scale better

 

Updates

* improvements to UI

* updated readme

 

New

* version number now displayed on Settings tab - helps when troubleshooting

* exclude locations is now point and click - user requested feature

* since you need a Service Account everywhere it now completely ignores exclusions

* local computer Service Account management - user requested feature

--- initial release is only for non-domain computers

--- 1 option: on/off

--- when on it looks for new computers every hour and adds a service account

--- if the Location does not have an admin account assigned it will be assigned the local account

Edited by Guest

Share this post


Link to post
Share on other sites

Questions I need your input on:

 

How often should I check for new computers to add the local service account to?

---- i think every 4 hours

 

I'm planning on adding automated testing and repair of the service account. How often should it run?

---- i think once a day

 

Should a local service account be added to domain joined computers also?

---- i can see where that would be useful for recovery purposes

 

Any suggestions for User Interface improvements?

Share this post


Link to post
Share on other sites

Anyone else have trouble adding a check to more than 17 locations exclusions under the 'Manage Locations' tab?

 

No matter what I do, I try checking more than 17, save and then close and reopen the window to find the setting gone.

Share this post


Link to post
Share on other sites
No matter what I do, I try checking more than 17, save and then close and reopen the window to find the setting gone.

 

My bad, only allowed 50 characters in that field. I'll have to figure out a way to fix it in an update.

 

How comfortable are you in SQL :)

ALTER TABLE plugin_itsc_msp_accounts_settings MODIFY Exclude_Locations VARCHAR(500);

Share this post


Link to post
Share on other sites

Fantastic, that fixed it!

 

Do you know what happens if I add an account into the MSP Account plugin that is already an AD account? Does it just ignore the account creation and just change the password?

 

I ask because I already have accounts at the clients locations. I would love to have this plugin take over with setting passwords for accounts that are already in place.

Share this post


Link to post
Share on other sites

Does this plugin automatically set all the accounts it manages as Administrators? Can it be configured to not grant admin privileges to the accounts it maintains?

Share this post


Link to post
Share on other sites

I would like to give techs non-admin access to client resources by default, and then only elevate them temporarily after an approval to perform an action

Share this post


Link to post
Share on other sites
Questions I need your input on:

 

How often should I check for new computers to add the local service account to?

---- i think every 4 hours

 

I'm planning on adding automated testing and repair of the service account. How often should it run?

---- i think once a day

 

Should a local service account be added to domain joined computers also?

---- i can see where that would be useful for recovery purposes

 

Any suggestions for User Interface improvements?

 

 

Hey Mate,

 

Great plugin! We are going to start using this, probably only need a single login for each site, but will give us some future proofing as well!

 

I think the repair could be done either daily or weekly. Weekly should be enough.

 

Definitely good to have a local account on domain joined computers, especially if you get an issue like it loses its trust relationship.

 

 

I have a question,

With the service accounts, if the site has no AD will it then create the service account on each of the computers and set that to the site admin account?

I feel that is what it is saying, but not 100% sure.

 

On the manage users, will this only create the users for sites with AD?

I would only want it to make it in AD ones.

 

Also I gather with the service accounts, you will be able to see the password in the labtech passwords tab?

 

 

Thanks for your hard work on this, it is definitely valuable and an easy way to keep passwords changed.

Share this post


Link to post
Share on other sites
With the service accounts, if the site has no AD will it then create the service account on each of the computers and set that to the site admin account?

yes

 

 

On the manage users, will this only create the users for sites with AD?

yes

 

 

Also I gather with the service accounts, you will be able to see the password in the labtech passwords tab?

yes

 

 

:)

Share this post


Link to post
Share on other sites

One last question.

 

We want to use a main _Admin account for login to client sites. Is there a way we can do this and see the password that gets set by random?

 

Cause we have _Service to be used for each of the service accounts, and also _Admin which is for a main account to use, but no idea how we can find the password that gets set for that? (I guess without logging in to the admin LT user.

Share this post


Link to post
Share on other sites

reading some of the comments about not being able to install or uninstall the plugin I am wondering if the author could check that they have generated a unique plugin guid? I have seen that quite a few times and would account for some of the issues, usually its still using the hello world guid

Share this post


Link to post
Share on other sites
One last question.

 

We want to use a main _Admin account for login to client sites. Is there a way we can do this and see the password that gets set by random?

 

Cause we have _Service to be used for each of the service accounts, and also _Admin which is for a main account to use, but no idea how we can find the password that gets set for that? (I guess without logging in to the admin LT user.

 

 

Nope, not gonna do it. :)

The concept is that every user uses their own login so that there is accountability.

(you can cheat by using the Service Account. the password is stored in the Passwords tab of each Location.)

Share this post


Link to post
Share on other sites
reading some of the comments about not being able to install or uninstall the plugin I am wondering if the author could check that they have generated a unique plugin guid? I have seen that quite a few times and would account for some of the issues, usually its still using the hello world guid

 

oops, i'm sure that is it.

 

I'll release an update shortly.

 

Thank you.

Share this post


Link to post
Share on other sites

MrRat - There should probably be an option to set up a batch of accounts at the same time (during initial setup phase), I noticed that it hung my LT client for awhile when adding more than 5 users. Otherwise it seems to be a nice easy way to manage a lot of technician accounts.

 

Does this plugin require that the probe computer be a domain controller for the location?

Share this post


Link to post
Share on other sites
There should probably be an option to set up a batch of accounts at the same time (during initial setup phase)

you're right. I'll have to look into it and see how much effort it will take.

 

Does this plugin require that the probe computer be a domain controller for the location?

No. It searches the database for PDCs and doesn't care about the probe.

Share this post


Link to post
Share on other sites
What's the query for the PDC? I noticed a couple of former domain controllers were showing up.

 

Couldn't be any simpler; I just ask for the PDCs

SELECT Computers.ComputerID FROM Computers, v_extradatacomputers WHERE v_extradatacomputers.ComputerID = Computers.ComputerID AND v_extradatacomputers.`AD FSMO Roles` LIKE '%PDC Emulator%'

Share this post


Link to post
Share on other sites

Interesting. It appears that this table doesn't update very frequently or at all. It's still detecting one of my member servers as a PDC when i dcpromoed it almost a year ago.

Share this post


Link to post
Share on other sites
Interesting. It appears that this table doesn't update very frequently or at all. It's still detecting one of my member servers as a PDC when i dcpromoed it almost a year ago.

 

Look in the Computer Management screen on the Ignite tab and then the Computer Role tab under that. In AD FSMO Roles it should list PDC Emulator and a date at the end of the field. If that is incorrect or is out of date then Labtech is not updating computer roles like it should and you need to contact support.

Share this post


Link to post
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.


×
×
  • Create New...