Disallowing security-risk user permissions

Disallow security-risk permissions for all users except those individuals who really need them. You can change permissions for individual users by editing the user account. You can also use security roles to restrict permissions globally and easily assign a group of permissions just to users who need them.See Managing roles for details.

Security-risk permissions which should be disallowed are:

Place external calls when logged on via a trunk (under the Standard permission group)
Log on via trunk (Standard)
Log on via IP trunk (Standard)
Log on via station (Standard)
Forward or route calls to external numbers (Standard)
Return calls when logged on via a trunk (Standard)
Select a specific trunk for outbound call (Administration)

 

Enhancing password security
Setting up dialing restrictions
Making account logon more secure
Securing your phone system database
Securing SIP stations