New sysadmin inherited an insecure environment and is being blamed for every issue

0
0
Asked By MellowCedar47 On

I recently started as the only IT person at a small company and inherited an environment with very few restrictions or documented security policies. For example, users can currently be contacted by people from external domains. I raised this with my manager and recommended reviewing the trusted-domain and external-access settings, but I have not changed that configuration yet.

Since I started, two employees have blamed me whenever something behaves differently, usually saying it never happened before. Their latest claim is that I removed an external user from a chat. I checked the Purview audit data, and the removal record is associated with one of their accounts rather than mine. It is also possible that the other organization changed its own Teams settings, causing the user to disappear or stop syncing. I have not manually removed anyone.

They have escalated these accusations to my manager, although my manager has supported me and knows that this department has a reputation for bullying. My manager is not technical, and I report through People Operations rather than an IT department.

They also claim that several users from different external domains were removed, but my report only shows one person. I am trying to address genuine security risks without being blamed for unrelated issues.

How should I handle coworkers who are consistently accusatory? What is the best way to defend myself when audit logs contradict their claims? Should I continue recommending tighter external-access controls, or am I creating unnecessary conflict by raising the issue?

5 Answers

Answered By QuartzMango81 On

Make your manager your partner in this. Present the facts clearly, explain the risks and possible causes, and agree on what actions you are authorized to take. Since you are working alone in IT and your manager is nontechnical, keep the explanations business-focused: what could happen, how likely it is, and what a proposed fix might affect. You should not try to fight the political battle by yourself.

Answered By HarborKite58 On

Raising security concerns is part of your job, but separate recommendations from actual changes. External messaging is not automatically unsafe; the right configuration depends on the company’s collaboration needs, identity controls, guest settings, monitoring, and risk tolerance. Present management with the current state, the risks, and a few options rather than framing it as an emergency change that you need to make immediately.

Answered By NorthStarLime6 On

Document everything: proposed changes, approvals, incidents, audit results, and who reported each issue. A simple change calendar or ticket process can help. Before making system-wide changes, record the reason, expected impact, rollback plan, and approval. That gives everyone visibility and makes it much harder to claim that you secretly changed something.

VelvetRook29 -

Even a basic shared calendar or site for changes is enough to start. The important part is that changes are announced and traceable, not that the process is complicated.

Answered By CopperWillow14 On

A calm meeting with the two employees, your manager, and possibly People Operations could reset expectations. Ask them to bring specific examples, walk through the evidence, and agree that future incidents will be reported through a defined process instead of through personal accusations. If the behavior continues despite documentation and management support, then evaluate whether the company is willing to protect you. A workplace where nobody has your back is a much bigger problem than one difficult incident.

Answered By SunnyPebble302 On

When someone says you caused an issue, avoid arguing emotionally. Ask for the exact user, time, action, and symptoms, then compare that information with the audit records. Respond with something neutral such as, “I checked the logs for that account and time, and they show the removal came from this account. I did not make that change. We should also check whether the external organization changed its policy.” Keep the evidence and let your manager handle repeated accusations.

Related Questions

LEAVE A REPLY

Please enter your comment!
Please enter your name here

This site uses Akismet to reduce spam. Learn how your comment data is processed.