He Discovered a Secret Off-Books Server Violating Global Data LawsโThen Executed an Automated Compliance Wipe That Froze Corporate Operations

Pexels/Reddit
Sometimes knowing when to troubleshoot and when not to troubleshoot can really go a long way for tech employees!
This guy shares how he nukes a business just because he had to!
Check out the full story.
Today I nuked a business critical prod on purpose
Hi,
I’m a 3rd level supporter and backend admin for Microsoft onprem systems. AD, DFS, GPO, server OS. At least my official fields of work and I fight to keep it that way.
This is where it gets bad…
Today I caused a major problem on purpose by executing our default policies. No change involved.
We start with a high priority ticket about some guy needing rdp permissions on a group of business critical servers. Nothing special at first glance. Look up the groups and done, right? Nope.
The groups are there, but their reference user was not in them.
We have this same app also on VDI for some reason, so maybe he needed that? Reference user checks out with that security group. Better call the super important person that ordered the permissions to verify what they want.
“Hi Hosenkobold, he needs permission to those servers I mentioned.”
He knew this was going to be messy…
“But you as the reference user don’t have permissions to it. That confused me.”
“But I do!”
At this point, I had to put on my best pokerface as my mind began calculating how that was possible and how much damage control was needed. Boy, were my calculations underestimated.
I thanked the person and looked through the groups. We have tier 2 users for clients, tier 1 users for servers and well, tier 0 for important stuff. Only tier 1 users in the rdp groups. No other groups. This person shouldn’t be able to connect, according to our rules.
Now we go to checking the servers itself.
UH OH…
Truely, this can’t be happening. Only IT can change THAT and everyone was schooled on not doing it. But as I open the local rdp and admin groups, I see the horror. Dozens of tier 2 users with permissions on the server, baked directly into the local groups.
GPO should remove them though. But well, GPO got exceptions build in to keep these users. Someone truely violated security policies. Better call my boss to ask what to do.
“Make screenshots and nuke it. This is done wrong and is against several policies.”
“Nuke it? That will take down access to a major part of the company and cripple it.”
“I’m already writing the mail. They can complain with security and federal security requirements. Who did it?”
That’s INSANE!
“Derp Derpson.”
“We’ll have a meeting in 30 minutes with him. Disable his accounts and bring the screenshots somehow to the meeting room.”
I got so much respect for my boss today and an oddly satisfying feeling about purging such a violation from our systems. And we got a new open position for senior system engineer for some unknown reason.
YIKES! That sounds like some trouble.

Sign up to get our BEST stories of the week straight to your inbox.
Let’s find out what folks on Reddit think about this one.
This user has had a very similar experience!

This user has an important question for this person!

This user knows how good it must feel to nuke it instead of fixing it!

If you enjoyed this story, check out this post about an accountant who sticks to 40-hour weeks after overtime guidance, and finds he likes it.
This user wants to know what happened next!

This user has decoded the real reason for nuking the system!

Somebody knows how to deal with stressful situations!
Enjoyed this story?

Sign up to get our BEST stories of the week straight to your inbox.



