Go Back   BlackBerry Forums at CrackBerry.com > BlackBerry Professionals > BlackBerry Administrators

Reply
 
LinkBack Thread Tools Display Modes
  #1  
Old 06-12-2009, 07:43 AM
CrackBerry User
Device Model: 9530 (Storm)
Carrier: Verizon
 
Join Date: Nov 2007
Posts: 38
Default A little Advice would be appreciated...

I work for a government agency that has approximately 60 different departments...

Our IT department has about 145 people on the BES. However, in my particular department we only have about 3-4 people on the BES.

After reading a lot of articles on how intrusive the BES admin can be I have been tasked with the project of trying to find an alternative to the BES.

So my question is this..if we have a BES on an exchange server, if we wanted to pull off the BES and use something else is there anything else??

I have been reading about BPS, but don't fully understand how it works...

We have one guy who uses the redirector software that runs on his PC which he keeps up all the time, but that doesn't seem a good option...for many reasons...

The problem is some of the text messages we send, messenger messages etc that are sent are sent because prying eyes should not be able to see, as it can cause a safety risk (I don't really want to go into a lot of detail)...

Just looking not to get flamed (GET A PRIVATE PHONE etc.), but more or less ideas since I guarantee there is someone out there that is in a similar situation that has made it work..

Appreciate the time...and advice..
Reply With Quote
  #2  
Old 06-12-2009, 07:50 AM
Threefive's Avatar
CrackBerry Genius
 
Join Date: Apr 2008
Posts: 2,263
Default

Well I can say this when on a BES server the device is more secure than off of it. Also on the BES it is not like real time they have to send the logs off to be read and then they get sent back to them. Besides most BES admin don't sit there and go through everything, the only time they find something really is if you report a problem and they have to go digging. Be careful of how you proceed with this it could cost you your job.
Reply With Quote
  #3  
Old 06-12-2009, 01:38 PM
CrackBerry Abuser
Device Model: 9500 (Storm) and Bold
Carrier: Vodafone
 
Join Date: Jan 2009
Location: UK
Posts: 177
Default

If you use BES 5.0 you can make use of the role based administration that gives users the rights to administer the BES without being able to do anything to anybodys mailbox.

The admin roles in BES 5.0 can be adjusted so you only give the required user the minimum rights they need.

You can then restrict the number of users that knows the besadmin password.
Reply With Quote
  #4  
Old 06-13-2009, 10:56 AM
CrackBerry User
Device Model: 9530 (Storm)
Carrier: Verizon
 
Join Date: Nov 2007
Posts: 38
Default

I never knew that they had to send out the logs for them to be read and get them back before reading them??

I thought a BES admin could simply browse through "file folders" of some type or another and see what the user base is doing.

Appreciate the responses.
Reply With Quote
  #5  
Old 06-15-2009, 01:12 PM
CrackBerry User
Device Model: 9000
Carrier: Rogers
 
Join Date: Jun 2008
Posts: 93
Default

SMS are not logged real-time. They are looged in .CSV files on the BES server. From there it is a matter of who has rights to those folders. If your department has different security requirements, you could always get your own BES and remove rights to the log folder. Be aware that removing rights from users like Enterprise Admin can really mess up your system.

It does come down to the concept that admins that have access to user IDs giving them unfeterred access to data need to be trusted. You are trying to solve a people problem with technology.
Reply With Quote
  #6  
Old 06-15-2009, 08:39 PM
CrackBerry User
Device Model: 9530 (Storm)
Carrier: Verizon
 
Join Date: Nov 2007
Posts: 38
Default

Well put CanuckBB...The thing is if we already have one BES running, then even though I know it is possible to have two BES's running on one network, I know it is not generally a good thing. Right??

That is why I asked about another viable alternative..that we could run internally within our department.

Email forwarding isn't a viable alternative for several reasons. I am just surprised there isn't another alternative out there..
Reply With Quote
  #7  
Old 06-16-2009, 04:10 PM
CrackBerry User
Device Model: 9000
Carrier: Rogers
 
Join Date: Jun 2008
Posts: 93
Default

There is nothing wrong with running multiple BES, other that 1) the expense of the hardware and software, and b) the myriad of issues you will have trying to own a server on the AD domain in a government agency.

You also do realize that SMS is horribly insecure don't you?

If you need to send confidential information via a BB, use email. encrypted end-to-end and secure in the mail box.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



 
 Site Support | Accessory Order Support | App Store Support | Advertise | Newsletter | About Us

Creating smartphone communities
Android Central - Android reviews, news and forums Crackberry - Blackberry news, reviews and community TiPb - iPhone news, accessory reviews & forums
Pre Central - Palm Pre Review, News and Community Treo Central - Treo & Centro News and Forums WMExperts - Windows Mobile Reviews & News

The names RIM and BlackBerry are registered Trademarks of Research in Motion Limited.
CrackBerry.com is in No Way Affiliated with Research in Motion Limited.
Copyright ©2007-2009 Smartphone Experts. Terms and Conditions. Privacy Policy. All rights reserved.