Join Our 3 MILLION+ Members Today! Register Here | Login
Go Back   BlackBerry Forums at CrackBerry.com > BlackBerry Professionals > BlackBerry Administrators

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
    Thread Author   #1  
Old 06-12-2009, 06:43 AM
CrackBerry User
Device(s): 9650 (Bold)
Carrier: Verizon
 
Join Date: Nov 2007
Posts: 61
Likes Received: 0
Thanked 0 Times in 0 Posts
Default A little Advice would be appreciated...

I work for a government agency that has approximately 60 different departments...

Our IT department has about 145 people on the BES. However, in my particular department we only have about 3-4 people on the BES.

After reading a lot of articles on how intrusive the BES admin can be I have been tasked with the project of trying to find an alternative to the BES.

So my question is this..if we have a BES on an exchange server, if we wanted to pull off the BES and use something else is there anything else??

I have been reading about BPS, but don't fully understand how it works...

We have one guy who uses the redirector software that runs on his PC which he keeps up all the time, but that doesn't seem a good option...for many reasons...

The problem is some of the text messages we send, messenger messages etc that are sent are sent because prying eyes should not be able to see, as it can cause a safety risk (I don't really want to go into a lot of detail)...

Just looking not to get flamed (GET A PRIVATE PHONE etc.), but more or less ideas since I guarantee there is someone out there that is in a similar situation that has made it work..

Appreciate the time...and advice..
Reply With Quote Tip this Post
  #2  
Old 06-12-2009, 06:50 AM
CrackBerry Genius
Device(s): Many
 
Location: Global
Join Date: Apr 2008
Posts: 3,039
Likes Received: 2
Thanked 10 Times in 8 Posts
Default

Well I can say this when on a BES server the device is more secure than off of it. Also on the BES it is not like real time they have to send the logs off to be read and then they get sent back to them. Besides most BES admin don't sit there and go through everything, the only time they find something really is if you report a problem and they have to go digging. Be careful of how you proceed with this it could cost you your job.
Reply With Quote Tip this Post
  #3  
Old 06-12-2009, 12:38 PM
CrackBerry Abuser
Device(s): 9520 (Storm2)
Carrier: Vodafone
 
Location: UK
Join Date: Jan 2009
Posts: 222
Likes Received: 0
Thanked 0 Times in 0 Posts
Default

If you use BES 5.0 you can make use of the role based administration that gives users the rights to administer the BES without being able to do anything to anybodys mailbox.

The admin roles in BES 5.0 can be adjusted so you only give the required user the minimum rights they need.

You can then restrict the number of users that knows the besadmin password.
Reply With Quote Tip this Post
    Thread Author   #4  
Old 06-13-2009, 09:56 AM
CrackBerry User
Device(s): 9650 (Bold)
Carrier: Verizon
 
Join Date: Nov 2007
Posts: 61
Likes Received: 0
Thanked 0 Times in 0 Posts
Default

I never knew that they had to send out the logs for them to be read and get them back before reading them??

I thought a BES admin could simply browse through "file folders" of some type or another and see what the user base is doing.

Appreciate the responses.
Reply With Quote Tip this Post
  #5  
Old 06-15-2009, 12:12 PM
CrackBerry Abuser
Device(s): 9000
Carrier: Rogers
 
Join Date: Jun 2008
Posts: 342
Likes Received: 1
Thanked 4 Times in 4 Posts
Default

SMS are not logged real-time. They are looged in .CSV files on the BES server. From there it is a matter of who has rights to those folders. If your department has different security requirements, you could always get your own BES and remove rights to the log folder. Be aware that removing rights from users like Enterprise Admin can really mess up your system.

It does come down to the concept that admins that have access to user IDs giving them unfeterred access to data need to be trusted. You are trying to solve a people problem with technology.
Reply With Quote Tip this Post
    Thread Author   #6  
Old 06-15-2009, 07:39 PM
CrackBerry User
Device(s): 9650 (Bold)
Carrier: Verizon
 
Join Date: Nov 2007
Posts: 61
Likes Received: 0
Thanked 0 Times in 0 Posts
Default

Well put CanuckBB...The thing is if we already have one BES running, then even though I know it is possible to have two BES's running on one network, I know it is not generally a good thing. Right??

That is why I asked about another viable alternative..that we could run internally within our department.

Email forwarding isn't a viable alternative for several reasons. I am just surprised there isn't another alternative out there..
Reply With Quote Tip this Post
  #7  
Old 06-16-2009, 03:10 PM
CrackBerry Abuser
Device(s): 9000
Carrier: Rogers
 
Join Date: Jun 2008
Posts: 342
Likes Received: 1
Thanked 4 Times in 4 Posts
Default

There is nothing wrong with running multiple BES, other that 1) the expense of the hardware and software, and b) the myriad of issues you will have trying to own a server on the AD domain in a government agency.

You also do realize that SMS is horribly insecure don't you?

If you need to send confidential information via a BB, use email. encrypted end-to-end and secure in the mail box.
Reply With Quote Tip this Post
Reply
BlackBerry Forums at CrackBerry.com > > BlackBerry Professionals > BlackBerry Administrators   A little Advice would be appreciated...

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes