Helpdesk security

How Helpdesk security works

Helpdesk maintains a modest level of security for technician and administrator logins. It is not intended to achieve high levels of security.

When you log in as a technician or administrator, Helpdesk begins a session. The session will remain active until you log out, or Helpdesk is idle for longer than the session timeout. This value is a web server property that has a default value of 20 minutes. If your session does time out, you will need to log in again before you can use technician or administrative functions.

Maintaining separate logins

Helpdesk does not require you to have a unique login. which means that it is possible to accidently get two indentical logins.

When duplicate logins exist, only the first entry in the database will be considered by Helpdesk. It will never find the duplicate entry. The entry that it will find first will be the one created first.

If you login and find that Helpdesk identifies you incorrectly as another technician, then the login code for that technician is the same as yours. You will need to ask the other technician to change their password, or ask the administrator to change your login to solve this problem.

Login security

Helpdesk stores your login in the database in plain text. Helpdesk never displays your login, but it is possible for someone to open the database and retrieve your login. Therefore you should preferably not use your network logon password, or a password that is used to secure highly confidential information.

Automatic login

Helpdesk can log technicians and administrators in automatically by checking the network login. If the technician is logged into the network then she will not need to enter a login code to perform technician functions. If the technician is working on a user's PC and wishes to perform a technician function, then she will need to enter a login code as before.

This feature requires the administrator to enter the network login name in the Manage technicians menu option.