Being the CAD admin without being an IT admin

As a long time SOLIDWORKS user and developer of in-house SOLIDWORKS and PDM addins, I am constantly being stymied by our (typical) draconian IT department with respect to admin rights. I am the CAD admin, but I have no admin privileges on the network, or on my machine. This makes it difficult to get many things done in a timely manner:

Update SOLIDWORKS on my edsktop or one of my VMs - forget it
Update Visual Studio - Forget it
Build a Visual Studio project that registers for COM interop - nope, the registry is off limits
Remote in to a users machine to see what problem they are having - no way
Install any app of any kind - nope

On a good day, I can shoot a Teams message to one of the IT guys and they can remote in to my machine (or one of my many virtual machines) for the sole purpose of typing in their admin credentials. On a bad day, they gripe and require me to open a support desk ticket which takes longer to create than the task I’m asking them to perform.

So, fellow CAD admins, has anyone out there found a workable solution to this problem? It looks like Microsoft’s Endpoint Privilege Management and the new Windows 11 Administrator Protection could go a long way to giving me the access I need to do my job. Is anyone using these solutions or have an alternative that won’t hamstring my day to day activities?

1 Like

I’m not an IT admin by any means, but I do have enough local and network privileges to do what I need to do while involving IT as little as possible.

If I were you, I’d compile a time study of how long you have to wait on IT to allow you to do your job and how often it happens. The people that care about money may not appreciate the inefficiency.

1 Like

I had this issue many years ago and after much complaining they provided me with an AD account that was granted Admin rights on the PC’s on our domain. I basically built a business case as @AlexB mentioned which outlined what and why I needed it and the process in which it occurs (always urgent and in the midst of diagnosing an issue). IT manager didn’t even put up an objection once I did that.

A couple years ago they thought they would cut that off to reduce “security risk” and make it an “on demand” situation where I had to contact them with the PC name and the duration that I needed admin access… that lasted about a day. Even our IT techs pleaded my case to the security team as I take quite a load off of them supporting all the engineering apps.

2 Likes

Aa of about two years ago, we lost all admin rights on our PCs. Before everyone was in the local admin group so we could install or remove whatever. Luckily I still remote admin rights to my servers so I do some work there.

For local testing, we have an app called Admin By Request. Local Admin Rights, Managed » Admin By Request. We have some local IT guys that can approve so I can do quick testing, although we still have some stuff blocked that even this won’t override. If I must open a ticket with global IT, it can take days depending on what I’m requesting, if I even know what specifically to ask for. Sometimes I have 3 different IT departments on a call trying to figure out which IT policy/setting is causing the issue. They all have their own ticket SLA which punishes them based on time to respond and resolve so they bounce the ticket around alot.

the pain of it. I did not have admin rights when I started, I finally got them so I can modify SolidWorks without having to go thru IT. I don’t do anything to modify the computer but to just add a search path for SolidWorks requires admin rights. So it is nice not having to send in a ticket.

I had admin rights on my computer for years without any issues. Then that went away. However, our IT department has a process in place where when I (or anyone else in our organization) try to do something that requires it they get a notice, and they generally approve it and give me temporary access within a few minutes. I don’t know how long it lasts, but it’s always lasted as long as I needed it.

I believe it’s some software that I assume is widely available. I can find out the name if you’d like.

Of course if your IT people are just a bunch of horse’s a**es we can’t help with that.

2 Likes

Thanks god I am still enjoying the shadow IT status.

2 Likes