Prompted by recent security breaches across MSP-industry vendors, a walkthrough of how to lock down API user accounts in Autotask, which default to full system-admin access.
hey everyone in light of the recent security breaches with some vendors in the MSP industry now is the time for you to be locking down your API accounts within the order task PSA tool so in this video I show you how [Music] everyone Chris Timm here in this video I'm going to show you how to lock down your API user accounts in Auto task so by default when you set these up in the PSA they always use the system admin account which has full access to everything inside all the tasks so in the I would say normally unlikely event of a breach um you know these these could be compromised so what we want to make sure is that you locking these down so that um you know in the unlikely event of a breach you're going to at least make sure that the data is safe and secure and that these other third-party applications are not able to access anything in order to ask so let's go and take a look at how we would do this so the very first thing we want to do from here is we want to click on or at least hover on this little Auto task icon click on the admin and then we want to go into account settings and users and then here under resources and users and resources and users again so you can see we have a bunch of different API accounts in here so by default all of these are set up to be system accounts so you can see um system so what I want to do is to show you where you would actually see those so again from the resources and users section under security levels if we were to go into this API system user accounts in here and simply try and edit it it will come up and tell you that it's not editable but something I wanted to show you by default it has full admin access to everything on your system it also has full admin access to be able to delete accounts from the CRM to delete opportunities to delete notes attachments also has the ability to go in and delete any information on the service desk as well as ADD tickets and do all of that so is really really important that we make sure that we lock these things down so that they don't have the ability to do that so let's go and actually take a look at one of these API users that I have set up on here so if we go back to the users in here if we were to look at something like for example you know let's just look at one of these Integrations so I know that paxade for example doesn't need to create tickets it also um you know doesn't need any admin access so instead of giving it the full API user system account what I'm going to do is I'm simply going to come in here and I'm going to say back to my security levels and then I'm going to right click copy the security level and then I'm going to go ahead and do something like saying maybe just call this you know pax8 pax8 API so what I can then do is go well what does pax8 need access to so by default pax8 obviously needs access to be able to certainly view contracts and and add some information to contract so I'm going to give it the ability to keep all of that from a CRM perspective it needs the ability to add accounts and contacts but what it doesn't need is is any ability to do anything necessarily with opportunities or sales orders or any of these so I'm just going to give it no view access to any of the stuff so you can see how I can simply just come in here and give it no view access to any of this um and I'm just going to come in here and it certainly doesn't need any access to delete any of those things so I'm just simply going to give this a none and then from here I'm going to go back in and I'm going to say it doesn't really need to do anything with inventory so instead of me coming in and changing all of these things um you know selecting these drop down lists and changing them manually what I am actually going to do at this point is I'm going to go ahead and um and and just say up here I'm going to give it no permission so when I do no permission you'll see that it basically just delete or you know get rid of everything makes this nun gets rid of all these these check Boxes Etc needs no permission to projects it also doesn't really need to do anything with the service desk either but you can see by default it has the ability to delete all tickets so I just give it no permission to service desk has no permission to timesheets or reports and certainly doesn't need any access to any of the admin stuff so you can just turn all of this off and now when I hit save and close what you'll see at this point is I now have a new API user account specifically for pax8 so if we go back into here and then I go back to resources and users and I now go and find my pax8 integration and here I can see my Pax 8 integration click on the edit button and I'll change the security level here to be this pax8 API that I gave it hit simply hit save and close and that's it it is now changed and you can see that it now has its own specific security level and doesn't have the ability to go in and delete any of that stuff so I hope this was useful if you find this video useful I would really really appreciate it if you could give it a like subscribe to this channel it really does help me make more of these so thank you very much for watching and I look forward to seeing you on the next video [Music] thank you [Music]
Get in touch and we'll talk through how it applies to your MSP.
Let's Talk