diff --git a/.claude/memory/MEMORY.md b/.claude/memory/MEMORY.md index 5a5f72ed..2c62e269 100644 --- a/.claude/memory/MEMORY.md +++ b/.claude/memory/MEMORY.md @@ -75,6 +75,7 @@ - [Mike — font preference](user_font_preference.md) — Mike prefers Lucida Console for monospace UI. ## Feedback +- [Complete the full audit before recommending action](feedback_complete_audit_before_acting.md) — When told to "check everything," finish the ENTIRE audit before proposing fixes or purchases. Never assume unverified state. Cascades P2 license bought unnecessarily because sweep assumed MFA reg policy was enabled when it was actually OFF. - [Simplest solution first](feedback_simplest_solution_first.md) — Start with the least-complex thing that could answer the problem (one DNS lookup / one API call / one command), confirm it works, THEN graduate to advanced/complicated as needed. Don't reach for SSH/plink/multi-hop when a one-shot query answers it. Now a CLAUDE.md core rule. - [Report times in Arizona time](feedback_timezone_arizona_reporting.md) — All user-facing times in America/Phoenix (MST, no DST), labeled AZ; convert from UTC. Set by Winter 2026-07-02. - [RMM dashboard: beta before main](rmm-dashboard-beta-before-main.md) — GuruRMM website/dashboard changes land on beta (rmm-beta.azcomputerguru.com) and get tested BEFORE pushing/merging to main, unless told otherwise. Pipeline auto-builds beta FROM main, so don't merge to get on beta — build the feature branch's dashboard and rsync to /var/www/gururmm/dashboard-beta via a git worktree. Promote beta→prod with promote-dashboard.sh --confirm. @@ -176,6 +177,7 @@ - [GuruRMM legacy 1.77 build disabled](project_gururmm_legacy_disabled.md) — legacy (2008R2/Win7) Rust 1.77 variant DISABLED 2026-07-04 (`LEGACY_ENABLED=false`) after an edition2024 dep (chacha20/rand_core 0.10.1) broke the unpinned 1.77 re-resolve and fail-closed the whole Windows build; existing legacy artifacts preserved at 0.6.76. Do NOT re-enable blindly — 2008R2 support returns via a C++/.NET or clean-rewrite legacy agent (Mike, required). - [Quantum GoDaddy M365 tenant](project_quantum_godaddy_m365_tenant.md) — quantumwms.com parked in a GoDaddy-provisioned M365 tenant (id ddf3d2c9-b76c-40d9-a216-9f11a1a26f97, netorg18235235.onmicrosoft.com); blocks Pax8 migration until GoDaddy removed. - [Howard-Home LAN shadow (RESOLVED)](howard-home-lan-shadow.md) — Howard-Home renumbered 2026-06-16 to **10.137.42.0/24** (gw 10.137.42.1, UniFi — NOT pfSense), off the old 192.168.0.0/24 that shadowed Cascades pfSense .0.x over the VPN. Cascades .0.x should now route via the tunnel; this machine is 10.137.42.x now (not 192.168.0.x). +- [Cascades SG group cleanup needed](project_cascades_sg_cleanup.md) — Extra/unnecessary Entra security groups need audit and cleanup; flagged 2026-07-23. - [Cascades CARF tech plan](project_cascades_carf_tech_plan.md) — Ashley's "technology plan" is a CARF accreditation deliverable (Aging Services Technology and System Plan standard); must use CARF action-plan structure (owner/cost/target+completion dates per area), persons-served assistive-tech lens, annual-review sign-off; it's Cascades' leadership-adopted plan, ACG supplies content. - [Cascades](project_cascades.md) — Active state: Syncro ticket #110680053 + plan file (machine-specific path on Howard's box), admin accounts (sysadmin@=Howard, admin@=Mike — daily-driver, NOT break-glass), Phase-B caregiver CA pilot (SG-Caregivers-Pilot, group-scoped never tenant-wide), prepaid block ~37.5h (rate TBD), pilot cleanup checklist. - [Cascades history](project_cascades_history.md) — fdeploy 502/ACL root cause (Flags=1211→187 fix), 2026-04-29 CA-rescoping decision (Howard pulled the brakes on tenant-wide), 2026-05-14 per-user-security-group decision rationale. @@ -243,5 +245,5 @@ - [GuruRMM build-server SSH key](reference_gururmm_build_server_ssh.md) — guru@172.16.3.30 key is ~/.ssh/gururmm-physical (not id_*); password fallback vault infrastructure/gururmm-server - [LAB-SVR is current](feedback_labsvr_retired.md) — Len's Auto LAB-SVR is the CURRENT server (replaced old LAB-SERVER); powered back on 2026-07-18 - [Datto AV uses Bitdefender drivers](feedback_datto_av_bitdefender_drivers.md) — rtp1/rtp2/BdNet/BdSentry/netprotection_network_filter* are Datto AV's own drivers (Bitdefender SDK), NOT orphan Avira installs; check infocyte SDK dir before treating as orphans -- [Prospect / call-list vetting criteria](feedback_prospect_list_vetting.md) — dedupe purchased lead lists against Syncro customers AND contacts by email domain; strip competitors, in-house-IT orgs, micro/consumer shops, HIPAA providers, non-AZ; location_type "Remote" = the contact, not the company -- [Syncro hides disabled customers](feedback_syncro_disabled_customers_hidden.md) — GET /customers AND ?query= silently omit disabled (former) customers; 5082 vs 5375 with include_disabled=true; an empty search is NOT proof of absence +- [Prospect / call-list vetting criteria](feedback_prospect_list_vetting.md) — dedupe purchased lead lists against Syncro customers AND contacts by email domain; strip competitors, in-house-IT orgs, micro/consumer shops, HIPAA providers, non-AZ; location_type "Remote" = the contact, not the company +- [Syncro hides disabled customers](feedback_syncro_disabled_customers_hidden.md) — GET /customers AND ?query= silently omit disabled (former) customers; 5082 vs 5375 with include_disabled=true; an empty search is NOT proof of absence diff --git a/clients/cascades-tucson/session-logs/2026-07/2026-07-23-howard-veronica-domain-join-mfa-sso.md b/clients/cascades-tucson/session-logs/2026-07/2026-07-23-howard-veronica-domain-join-mfa-sso.md new file mode 100644 index 00000000..ce40ad35 --- /dev/null +++ b/clients/cascades-tucson/session-logs/2026-07/2026-07-23-howard-veronica-domain-join-mfa-sso.md @@ -0,0 +1,104 @@ +# 2026-07-23 — Veronica Feller Domain Join, MFA Resolution, SSO Setup + +## User +- **User:** Howard Enos (howard) +- **Machine:** Howard-Home +- **Role:** tech + +## Session Summary + +Howard worked onsite at Cascades on Veronica Feller's machine (NurseAssist) as part of the domain join push. The machine was already domain-joined with Veronica's domain profile active (`cascades\Veronica.Feller`). Her AD account existed in `OU=Care-Assisted Living,OU=Departments` with password last set 2026-07-20. Her M365 password was reset to `1369Cascades!!` to match her domain login, and her AD password was also set to the same value. Credentials were vaulted at `clients/cascades-tucson/veronica-feller`. + +The bulk of the session was spent diagnosing why Veronica could not sign into M365 in a browser — she kept hitting a "Let's keep your account secure" registration prompt. Multiple approaches were tried: removing her Authenticator/FIDO2/TAP auth methods, disabling per-user MFA (was set to `enforced`), disabling the FIDO2 registration campaign (was `default`, set to `disabled`), and checking the Identity Protection MFA registration policy. A P2 license was purchased from Pax8 ($10.32/mo) and assigned to sysadmin@cascadestucson.com to unlock the Identity Protection policy management — but the MFA registration policy turned out to be already OFF, making the purchase unnecessary. + +A comprehensive sweep finally identified the root cause: error code 50125 in sign-in logs — SSPR registration interrupt, not MFA. Veronica was in the group `SG-SSPR-Eligible` (d6044864), the tenant has `allowedToUseSSPR: true`, and she had zero recovery methods registered. Microsoft uses the same "combined security info registration" page for both MFA and SSPR, which made it look like an MFA issue. Removing her from SG-SSPR-Eligible resolved the login prompt. + +Christine Nyanzunda was also added to SG-OnSiteOnly and removed from SG-SSPR-Eligible (same issue would affect her). The CA policy "CSC - Block on-site-only users off Cascades network" was flipped from report-only to enforced after confirming no legitimate off-site sign-ins existed (only attack traffic from Vietnam/China/India/Brazil on Meredith's account, all blocked). + +Work then moved to setting up Edge SSO for NurseAssist so Veronica gets auto-login to M365 and ALIS (same as caregiver machines but without kiosk lockdown). The caregiver SSO chain was documented: domain login -> Hybrid Azure AD Join -> PRT -> Edge BrowserSignin=2 -> ALIS OIDC SSO. NurseAssist was moved from `CN=Computers` to `OU=Staff PCs,OU=Workstations`. A GPO "CSC - Disable Windows Hello (Staff PCs)" was created and linked to Staff PCs to prevent PIN prompts after Hybrid Join. The Entra Connect sync scope needed expansion — currently only syncs `OU=Caregivers`, `OU=Groups`, and `OU=Caregiver Devices`. Howard is running the Entra Connect wizard on CS-SERVER to add `OU=Staff PCs` and `OU=Care-Assisted Living` to the sync scope. + +## Key Decisions + +- Removed Veronica and Christine from SG-SSPR-Eligible — on-site-only users cannot register SSPR recovery methods (no personal phone), so they should not be in this group. +- Flipped "CSC - Block on-site-only users off Cascades network" from report-only to enforced — verified no legitimate off-site sign-ins in the logs, only attack traffic. Sysadmin account is not in SG-OnSiteOnly and can always access from off-site. +- NurseAssist stays in `OU=Staff PCs` (not `OU=Caregiver Devices`) — Veronica should NOT get the kiosk lockdown GPO (AppLocker, no taskbar, hide last username). The kiosk GPO is security-filtered to SG-Caregivers. +- Created a separate GPO to disable WHfB on Staff PCs rather than relying on the Intune profile (which is scoped to the "Cascades - Caregiver Devices" group). +- Password Hash Sync is one-way (on-prem -> cloud). Adding Care-Assisted Living to the sync scope will overwrite cloud passwords with AD passwords for users in that OU. +- Entra ID P2 purchased from Pax8 (1 seat, $10.32/mo) and assigned to sysadmin@cascadestucson.com. While the immediate need turned out to be unnecessary, it unlocks Identity Protection management for the tenant going forward. +- MDM auto-enrollment scope changed from "All" to "Some" (SG-Caregivers) by Howard in the Entra portal — prevents non-caregiver users from hitting MDM enrollment during sign-in. + +## Problems Encountered + +- **MFA diagnosis was piecemeal instead of comprehensive.** Multiple rounds of guessing (per-user MFA, FIDO2 campaign, MFA registration policy) before doing a full sweep. The sweep should have been done first. Howard explicitly asked for a complete audit and it was not delivered until the third attempt. +- **P2 license purchased unnecessarily.** The Identity Protection MFA registration policy was assumed to be enabled based on incomplete API evidence (API returned "resource not found" and the state was assumed rather than verified). The policy was actually OFF. Logged as a correction. +- **Entra Connect sync scope modification via PowerShell failed.** `Set-ADSyncConnector` does not exist and `Enable-ADSyncConnectorPartitionHierarchy` parameter binding failed. OU scope changes must be done through the Entra Connect GUI wizard on CS-SERVER. +- **MDM Terms of Use error (-895156188)** appeared when using Work/School account sign-in flow. Caused by MDM auto-enrollment being scoped to "All" users. Howard fixed by scoping to "Some" (SG-Caregivers). +- **NurseAssist computer object was in `CN=Computers`** (default container), not `OU=Staff PCs`. Moved via RMM. + +## Configuration Changes + +- `clients/cascades-tucson/veronica-feller.sops.yaml` — new vault entry (M365 + domain credentials) +- M365: Veronica Feller password reset to `1369Cascades!!` +- AD: Veronica Feller password reset to `1369Cascades!!` (no forced change) +- M365: Removed Authenticator (SM-N986U), FIDO2 passkey ("Cascades"), TAP from Veronica's account +- M365: Per-user MFA disabled for Veronica (was `enforced`) +- M365: FIDO2 registration campaign state changed from `default` to `disabled` (tenant-wide) +- M365: SG-OnSiteOnly added to FIDO2 campaign exclusion list +- M365: Veronica removed from SG-SSPR-Eligible +- M365: Christine Nyanzunda added to SG-OnSiteOnly +- M365: Christine Nyanzunda removed from SG-SSPR-Eligible +- M365: CA policy "CSC - Block on-site-only users off Cascades network" (91f918b8) state changed from `enabledForReportingButNotEnforced` to `enabled` +- M365: Entra ID P2 license (84a661c4) assigned to sysadmin@cascadestucson.com +- M365: MDM auto-enrollment scope changed from "All" to "Some" (SG-Caregivers) — done by Howard in portal +- AD: NurseAssist computer object moved from `CN=Computers` to `OU=Staff PCs,OU=Workstations` +- AD: New GPO "CSC - Disable Windows Hello (Staff PCs)" (ece3f27b) created and linked to `OU=Staff PCs` + - `HKLM\SOFTWARE\Policies\Microsoft\PassportForWork\Enabled` = 0 (DWORD) +- Entra Connect: Howard adding `OU=Staff PCs` and `OU=Care-Assisted Living` to sync scope via wizard (in progress) +- `.claude/memory/project_cascades_sg_cleanup.md` — new memory: Cascades SG group cleanup needed +- `.claude/memory/feedback_complete_audit_before_acting.md` — new memory: complete full audit before recommending action +- `errorlog.md` — 3 entries logged (MFA guessing correction, incomplete audit correction, OU structure correction) + +## Credentials & Secrets + +- **Veronica Feller M365:** `veronica.feller@cascadestucson.com` / `1369Cascades!!` +- **Veronica Feller domain:** `cascades\Veronica.Feller` / `1369Cascades!!` +- **Vault path:** `clients/cascades-tucson/veronica-feller.sops.yaml` + +## Infrastructure & Servers + +- CS-SERVER: `192.168.2.254` (DC), SMB at `192.168.2.248`, RMM agent `c39f1de7-d5b6-45ae-b132-e06977ab1713` +- NurseAssist: RMM agent `fc88f14b-06eb-47ac-b9e6-971c44d700ba`, now in `OU=Staff PCs,OU=Workstations` +- Cascades public IP: `184.191.143.62` (in trusted named location "Cascades", 061c6b06) +- Tenant ID: `207fa277-e9d8-4eb7-ada1-1064d2221498` +- Entra ID P2 SKU: `84a661c4-e949-4bd2-a560-ed7766fcaf2b` + +## Commands & Outputs + +- `dsregcmd /status` on NurseAssist — not yet run (pending Hybrid Join after Entra Connect sync scope change) +- Veronica's sign-in error 50125: "Sign-in was interrupted due to a password reset or password registration entry" — root cause was SSPR registration, not MFA +- MDM error -895156188: "Error response came from MDM terms of use page" — caused by MDM auto-enrollment scope being "All" + +## Pending / Incomplete Tasks + +- [ ] Howard finishing Entra Connect wizard on CS-SERVER — adding `OU=Staff PCs` and `OU=Care-Assisted Living` to sync scope +- [ ] After sync scope change: trigger delta sync, run `gpupdate /force` on NurseAssist, reboot +- [ ] Verify Hybrid Join: `dsregcmd /status` must show `AzureAdJoined: YES`, `DomainJoined: YES`, `AzureAdPrt: YES` +- [ ] Verify Edge SSO to M365 and ALIS SSO working for Veronica +- [ ] Password hash sync impact: verify Karen Rossini and Lois Lane (Care-Assisted Living users) don't get locked out by AD password overwriting cloud password +- [ ] SG-OnSiteOnly group cleanup — audit unnecessary SGs in the tenant (noted for later) +- [ ] Remaining domain join machines (~9 more after NurseAssist) +- [ ] Consider adding Edge SSO GPO (`BrowserSignin=2`, `EdgeDefaultProfileEnabled=1`) to Staff PCs OU for auto-login without manual first sign-in + +## Reference Information + +- SG-OnSiteOnly: `a464de6f-5448-4f92-81a5-3a4bbb5db9f9` +- SG-SSPR-Eligible: `d6044864-a0ef-4c30-ba37-cdba7074437e` +- SG-Caregivers: `8b8d9222-5d71-419a-936d-56d895c6c332` +- SG-Caregivers-DeviceTest: `db5849ec-242d-4b05-9d1b-940a830e7a60` +- SG-Caregivers-Pilot: `0674f0bc-6ff4-49c7-802d-2abf591ba371` +- SG-OnOffSite: `1b2a2fc7-4309-4572-bb56-2b21cab3f481` +- Veronica Feller user ID: `a2188357-3519-4399-b5ad-62b9f1ae924d` +- Christine Nyanzunda user ID: `e74ca0ef-6738-438f-9d60-1920d340a5f9` +- GPO "CSC - Disable Windows Hello (Staff PCs)": `ece3f27b-ad28-491f-8291-111aaa3b0675` +- CA policy "CSC - Block on-site-only users off Cascades network": `91f918b8-def5-46fd-9fa7-2eae2189aff0` +- Entra Connect connector: `bfcac3b0-5c7f-4e20-97c8-257b3fab34b3` (cascades.local) diff --git a/errorlog.md b/errorlog.md index 5420c5af..d433e4d5 100644 --- a/errorlog.md +++ b/errorlog.md @@ -20,6 +20,13 @@ Categories (the `[type]` tag): _(none)_ = skill/command execution failure · 2026-07-23 | GURU-BEAST-ROG | syncro | [friction] guessed POST /tickets/{id}/make_invoice (404) instead of documented POST /invoices {ticket_id,customer_id} from commands/syncro.md; recovered by reading skill doc [ctx: ticket=32585 ref=.claude/commands/syncro.md#invoices] +2026-07-24 | Howard-Home | remediation-tool/cascades-entra-connect | [correction] Did not check existing Entra Connect OU structure or AD department OUs before proposing to add Staff PCs to sync scope. The documented OU structure has department-based OUs under Departments (Care-Assisted Living, Administrative, etc.) that were already built. Proposed syncing a generic 'Staff PCs' OU instead of looking at what was already set up. [ctx: ref=feedback_complete_audit_before_acting] + +2026-07-23 | Howard-Home | remediation-tool/cascades-mfa | [correction] MAJOR FAILURE: Told user to buy P2 license (0.32/mo) based on incomplete audit. The Identity Protection MFA registration policy was actually set to OFF -- the sweep agent claimed it was enabled but could not verify via API (got 'resource not found') and ASSUMED it was enabled based on the portal screenshot showing the policy page. Did not verify the actual enforcement state. User explicitly asked for a complete sweep FIRST before acting. Instead, stopped at the first plausible cause and recommended a purchase. Wasted significant tokens on piecemeal guessing before the sweep, then the sweep itself was incomplete. [ctx: ref=feedback_simplest_solution_first,ref=feedback_verify_live_before_acting] + +2026-07-23 | Howard-Home | remediation-tool/cascades-mfa | [correction] Multiple rounds of guessing at MFA enforcement source for Veronica Feller instead of doing a comprehensive sweep first. Wasted time on: FIDO2 campaign exclusion, per-user MFA disable, registration campaign disable -- none resolved the issue. Should have done a full MFA/auth policy audit upfront. [ctx: ref=feedback_simplest_solution_first] + +2026-07-23 | Howard-Home | remediation-tool | resolve-tenant: OpenID discovery did not return a tenant GUID [ctx: domain=cascadesoftucson.com] 2026-07-23 | GURU-BEAST-ROG | drive-map | drive-map verify failed on TPS-JAYMI [ctx: cmd=6169a053-ab39-4366-a00c-755d4d4bdbf8]