sync: auto-sync from HOWARD-HOME at 2026-07-17 10:24:46

Author: Howard Enos
Machine: HOWARD-HOME
Timestamp: 2026-07-17 10:24:46
This commit is contained in:
2026-07-17 10:25:18 -07:00
parent 56a8b9f2ab
commit 22c54f7307
13 changed files with 474 additions and 17 deletions

View File

@@ -11,6 +11,23 @@
> CS-SERVER EDR installed, ticket table reconciled against Syncro (0 open as of 7/10).
> The "Live snapshot" below is still the 6/24 AD-vs-RMM diff -- domain-join states are
> per-machine current in the wiki's "Migration phase status" table.
>
> **REFRESHED 2026-07-15 — FINISH-LINE PASS** (full live verification sweep: Graph/M365,
> Datto EDR, UniFi, MSP360, DNS — all evidence in the 7/15 session log + wiki recompile):
> - **CARF Technology Plan FINALIZED** (`docs/proposals/cascades-technology-plan-2026-07-15.md`)
> — this roadmap is the execution engine behind it; plan targets (30/60/90 day) map to the
> workstreams below.
> - **jodi.ramstack DECOMMISSIONED 7/15** (disabled + sessions revoked + suspended-Standard
> license reclaimed; mailbox was already deprovisioned by the suspended sub — no data in-tenant).
> Suspended Standard now 29 consumed.
> - **EDR verified 35/35** incl. CS-SERVER; email auth (SPF/DKIM/DMARC) verified; ALIS SSO
> verified (secret good to 2028); 77 APs confirmed; voice VLAN exactly 37 devices.
> - **Synology -> CS-SERVER share sync IS live and working** (wiki was stale; corrected).
> - **New workstreams added**: WS8 (SharePoint/Teams HIPAA migration), WS9 (ALIS online
> payments), WS3 step 3b (nurse-station phone-parity shared login).
> - Prepaid block: **21.5 hrs** (live 7/15).
> - Goal restated: **close every workstream out** — the sequence at the bottom is the
> finish order.
---
@@ -143,9 +160,11 @@ access matrix; Synology retired as primary.
## Workstream 3 — HIPAA caregiver lockdown — GO-LIVE (highest value, mostly built)
**[UPDATED 2026-07-13]** The 7/1 CA cutover put caregivers in an **interim posture**: all 35
**[UPDATED 2026-07-15]** The 7/1 cutover put caregivers in an **interim posture**: all 35
`SG-Caregivers` may sign in on desktops AND phones, **on-network only** (`e35614e1` off-network
block + `7d491c7a` 8h sign-in frequency enforced; `SG-Caregivers` excluded from MFA-for-all).
block — policy itself enabled since 2026-04-29 per live CA read 7/15, trusted IPs
72.211.21.217/32 + 184.191.143.62/32 — + `7d491c7a` 8h sign-in frequency enforced;
`SG-Caregivers` excluded from MFA-for-all).
The compliance-block policy `ede985e2` was **DISABLED 2026-07-01 — do not re-enable** (superseded
by the allow-list). Temp passwords are live for phone sign-in (must-change cleared fleet-wide 7/2;
`PSO-Caregivers` never-expire FGPP in place). Roster = **35** after the 7/1 reconcile.
@@ -164,6 +183,16 @@ Final lockdown = flip from test scope to real caregivers, one device at a time
after Win11 reinstall), NURSESTATION-PC (+ verify NurseAssist/Laptop4). NOTE: the device-lockdown
(auto-logoff) GPO only applies once machines are in `OU=Caregiver Devices` — until then desktops
caregivers use under the interim posture have NO auto-logoff enforcement.
3b. **[ADDED 2026-07-15, Howard] Nurse-station desktops = phone-parity shared login.** The TWO
nurse-station desktops — **NURSESTATION-PC + ASSISTNURSE-PC** (explicitly NOT the medtech
laptops) — get the same model as the caregiver phones: ANY caregiver signs in with their own
`cascades\` username, lands on ALIS via SSO, and sees the SAME standardized desktop shortcuts
to the SAME sites as the phones. Implementation: allow `SG-Caregivers` interactive logon on
those two machines; deploy the shortcut set via the `CSC - Caregiver Workstation` GPO
(per-machine, all-users desktop) so every profile is identical; no per-user profile
customization; auto-lock/sign-out from the device-lockdown GPO applies (step 6). Define the
canonical shortcut list from the phone home-screen set (ALIS + the same sites — capture the
list from a phone before building).
4. ALIS email-match the 35 caregivers + medtechs (ALIS staff Email = Entra UPN); ALIS records still
to create for Munezero/Cota/Robinson; Vallejo email-match; 7 discharged-record decisions;
turn off ALIS-native 2FA per user, then move to SSO-only (native login is a CA bypass path).
@@ -178,8 +207,12 @@ Final lockdown = flip from test scope to real caregivers, one device at a time
## Workstream 4 — M365
- **Relicense remaining suspended Business Standard users -> Business Premium** (Standard SKU is
SUSPENDED — time-sensitive). SPB now 45 seats enabled (Howard bought 11 on 6/30); 41 consumed as
of 7/1 — count seats before relicensing.
SUSPENDED — time-sensitive). Live 7/15: SPB 45 enabled / 41 consumed (4 free); suspended
Standard **29 consumed** after the jodi.ramstack reclaim — 29 users to move needs ~25 more SPB
seats OR a per-user needs pass (lighter licenses where full Office isn't needed — the CARF plan
Area 2 budgets ~$375575/mo for the mix). Count seats + decide mix before touching licenses.
- ~~Decommission jodi.ramstack~~ — **DONE 2026-07-15** (disabled, sessions revoked, license
reclaimed; mailbox already gone via the suspended sub — nothing recoverable in-tenant).
- **Create break-glass accounts (`breakglass1/2-csc@`) + enroll FIDO2 YubiKeys** — still not created
(confirmed 5/27); now a **prerequisite for the WS3 allow-list enforcement flip**.
- **Remove the standing Privileged Authentication Administrator role from the
@@ -194,15 +227,22 @@ Final lockdown = flip from test scope to real caregivers, one device at a time
## Workstream 5 — Server / infrastructure
- **Cloud backup (MSP360 -> ACG-backup): VERIFIED running 2026-06-24** (last run Success, 0 failed, 575 GB baseline in cloud, incrementals working). Still confirm it is image/bare-metal/system-state (looks file-level) + set retention. [GATE for any drive work]
- **Cloud backup (MSP360 -> ACG-backup): re-verified 2026-07-15** — daily file-level backup
running clean (incrementals current). **[WARN] The image/system-state side was ~10 days stale
at the 7/15 check** — confirm/repair the image plan + set retention BEFORE the SSD swap.
[GATE for any drive work]
- **CS-SERVER RAID -- CORRECTED 2026-06-24: HEALTHY, not degraded** (live OMSA: both mirrors Ok, all 5 disks Online, all LEDs green; the 6/15 degraded self-recovered). **NO emergency drive swap.** 1:0:4 = global hot spare (do not remove). **Planned** reliability upgrade: replace the 2 consumer 320 GB drives (esp. flaky WD 0:0:3) with the 2x enterprise SSD **already purchased**, on a scheduled window w/ confirmed image/system-state backup. **[WARN] PSU redundancy lost** -- one PSU not delivering, check onsite. Service Tag 9MQFTK1. Real fix = DC migration off the 16-yr-old R610.
- ~~Clean up old-MSP agent sprawl (Datto RMM/CentraStage + Datto EDR/Infocyte) thrashing the spindle~~
**DONE on CS-SERVER 2026-06-26** (full legacy Datto stack removed). **Current Datto EDR installed
on CS-SERVER 2026-07-13** (HUNTAgent=Running, cmd `0a60cac7`) — the DC is back under managed
endpoint protection. Fleet stragglers tracked in the wiki (DESKTOP-TRCIEJA BD_ACTIVE, laptop3/laptop1/
cascades-laptop reconcile, Syncro BD-deployment removal, GravityZone portal cleanup).
- Synology -> backup-only (Team Folder migration of the real shares; close the workgroup/Kerberos quirk).
- Synology -> backup-only: **the share syncs Synology -> CS-SERVER ARE set up and working**
(confirmed by Howard 7/15; wiki corrected). Remaining: finish the role flip (server is primary,
Synology becomes the onsite backup target per CARF plan Area 5) + close the workgroup/Kerberos quirk.
- Rotate the Synology signin-portal credential (was committed plaintext historically).
- pfSense: **AutoConfigBackup not enabled** (found 7/15) — enable it (config IS backed up via
our repo copy, but ACB gives point-in-time restore).
---
@@ -231,7 +271,9 @@ Final lockdown = flip from test scope to real caregivers, one device at a time
for offline resident TVs; identify the 17 unknowns + generic phones with John Trozzi.
- **#32319** WiFi Room 343 — relocate a floor-2/4 AP for coverage (unifi-wifi skill, site `va6iba3v`).
- **#32342** Copy Room switch — install + adopt into UniFi.
- ~25 switch ports linked at 100 Mbps but gig-capable (cabling/NIC sweep).
- Sub-gigabit sweep (live 7/15): **34 switch ports at 100 Mbps + 5 AP uplinks below gig**
cabling/NIC sweep, prioritize the AP uplinks. (Live UniFi count 7/15: **11 switches**, 77 APs,
voice VLAN exactly 37 devices.)
- *(Superseded)* Voice 5 GHz lock — now folded into the CSC ENT consolidation above (single
dedicated 5 GHz network for phones + sensors, not just a phone-side band lock).
@@ -243,19 +285,81 @@ Final lockdown = flip from test scope to real caregivers, one device at a time
---
## Suggested sequence (fastest path) — re-cut 2026-07-13
## Workstream 8 — M365 collaboration migration (SharePoint / Teams) — HIPAA lockdown
> Added 2026-07-15 (Howard): move Cascades onto SharePoint, Teams, and the wider Microsoft 365
> platform to lock down data access and advance HIPAA compliance. Pairs with the network upgrade
> work (WS6) and the domain migration (WS1/2) — the dept OU/group structure built there becomes
> the SharePoint/Teams permission model.
- **Scope/plan the migration**: department file shares (CS-SERVER `D:\Shares` + Synology) ->
SharePoint document libraries with role-based permissions mapped from the existing AD dept
groups; Teams for internal comms/collab (replaces ad-hoc channels); OneDrive for per-user files.
- **HIPAA guardrails first-class**: role-scoped access (same SG model as caregiver lockdown),
audit logging (ties into the WS4 audit-retention build), retention policies, DLP evaluation,
sensitivity labels for PHI, external-sharing OFF by default.
- **Licensing already supports it** — Business Premium (45 seats) includes SharePoint/Teams/
OneDrive/Intune/Purview basics; the WS4 relicensing moves the office staff onto it.
- Sequencing: after (or alongside tail of) the domain migration — don't build SharePoint
permissions on the pre-migration flat-share model. Candidate first movers: the newer
role-based shares (Executive restricted, Company Web Docs, ALDOCS).
- Synology then finishes its transition to backup-only (WS5) once shares live in SharePoint.
- Also on the plan doc: Copilot evaluation under HIPAA guardrails + the KPI dashboard's
SharePoint/Power BI Phase 1 (scheduled exports) land on this same platform.
---
## Workstream 9 — ALIS online payment system
> Added 2026-07-15 (Howard): get Cascades onto ALIS's online payment system (resident/family
> billing payments through the clinical-record platform, Medtelligent).
- **Scope with Medtelligent** — **scoping questions DRAFTED 2026-07-15**
(`docs/proposals/alis-online-payments-scoping-2026-07-15.md`, 18 questions: availability/
pricing/processor/PCI/BAA/ledger-posting/API/rollout). Next action: send to the Medtelligent
rep, loop in Jeff Bristol (accounting@) on replies. Q9 doubles as the BAA chase (Medtelligent
BAA unverified — feeds the area-4 BAA inventory regardless).
- Coordinate with the business office (Jeff Bristol / accounting@) on the AR workflow change
and family communication.
- IT-side items: SSO already live for ALIS (staff side); verify family-facing payment portal
access needs nothing on our network/identity side; add Medtelligent's payment processing to
the BAA/vendor tracker (plan area 4).
- Ties into the KPI dashboard (ALIS billing data is a Phase 1 export source).
---
## Finish sequence — re-cut 2026-07-15 (order of completion)
Everything below is scoped, built, or blocked on exactly one prerequisite — this is the
close-out order, not a wish list.
1. **2026-07-16 afternoon: offboard Juan Andrade** (disable + SG-Caregivers removal + license
reclaim) — coord todo `80716a98`. Do NOT disable before then.
2. **Break-glass accounts + strip the stranded PAA role** (Workstream 4) — prerequisite for the
allow-list enforcement flip; the tenant currently has live block policies and no break-glass.
3. **Caregiver lockdown go-live** (Workstream 3) — highest HIPAA value; the interim posture's real
control (device allow-list) is still report-only/test-scoped.
4. **M365 relicense remaining suspended-Standard users** (Workstream 4) — time-sensitive.
5. **Backup image/system-state confirm -> planned SSD swap** (Workstream 5) — single-DC risk.
6. **Remaining staff domain joins + dept drives** (Workstreams 1+2) + printer-share repoints /
Point-and-Print GPO fleet-wide (see wiki VLAN 20 section).
7. Network tail (CSC ENT device island, 100 Mbps ports) + audit-retention build.
2. **Break-glass accounts (`breakglass1/2-csc@`) + FIDO2 keys + strip the stranded PAA role**
(WS4) — THE blocking prerequisite for the allow-list enforcement flip; the tenant runs live
block policies with no break-glass today. Also the CARF plan's 30-day security item.
3. **Caregiver lockdown go-live** (WS3 steps 18, incl. 3b nurse-station phone-parity build) —
highest HIPAA value; the real control (`1b7fd025` allow-list) is still report-only/test-scoped.
Capture the phone shortcut list for 3b while onsite for the OU moves.
4. **M365 relicense the 29 suspended-Standard users** (WS4) — time-sensitive; decide seat mix
first (4 SPB free vs 29 to move).
5. **Repair/confirm the image/system-state backup -> scheduled SSD swap** (WS5) — image side was
~10 days stale on 7/15; single-DC risk until done.
6. **Remaining staff domain joins + dept drives** (WS1+2: ~10 machines left after readiness
blockers cleared) + printer-share repoints / Point-and-Print GPO fleet-wide (wiki VLAN 20).
Onsite batch: reboots, KFM unlinks, LAPTOP-DRQ5L558 on-LAN.
7. **Network tail** (WS6: CSC ENT device island incl. the ~79-client evacuation, 34-port +
5-AP-uplink gig sweep) + **audit-retention build** (WS4 — HIPAA 164.312(b) gap, approved
since 4/29).
8. **M365 collaboration migration (WS8)** — SharePoint/Teams scoping once the domain-migration
tail is done; permission model rides the dept OU/SG structure from WS1/2. Synology finishes
its backup-only role flip (WS5) behind it.
9. **ALIS online payments (WS9)** — vendor-driven, runs in parallel with everything above:
scoping questions are DRAFTED (`docs/proposals/alis-online-payments-scoping-2026-07-15.md`)
— send to Medtelligent when ready; business-office coordination (Jeff Bristol) is the long pole.
10. **Ticket-verify pass with Howard** (table below) — confirm the 6 closed-in-Syncro tickets
were actually completed; any that weren't fold back into WS1/2/6/7 and get done in step 67
onsite trips.
---