sync: auto-sync from ACG-TECH03L at 2026-04-20 00:02:36

Author: Howard Enos
Machine: ACG-TECH03L
Timestamp: 2026-04-20 00:02:36
This commit is contained in:
2026-04-20 00:02:38 -07:00
parent 27c2df201e
commit 41f5b6a21c
3 changed files with 90 additions and 1 deletions

View File

@@ -53,18 +53,36 @@ Senior living community. Active project: HIPAA-compliant folder redirection GPO
## Pending / Next Up
**Folder Redirection (ongoing):**
- [ ] EncryptData flag on `\\CS-SERVER\homes` share (HIPAA workitem — currently false)
- [ ] Second Life Enrichment machine folder redirection end-to-end
- [ ] Desktop + other folders redirection GPOs
- [ ] Matching GPOs for remaining departments
- [ ] Folder redirection GPO verification across all enrolled machines
**Intune MDM Rollout (started 2026-04-19, paused end of day 2026-04-20):**
- [x] Prereq gap check (`reports/2026-04-19-intune-mdm-prereq-gap.md`)
- [x] Create `MDMS@cascadestucson.com` service account - Business Premium, MFA, forwarding to howard@azcomputerguru.com (vault: `clients/cascades-tucson/mdm-service-account.sops.yaml`). Replaced an earlier mdm@ attempt that hit a Managed Play enterprise/consumer Google account collision.
- [x] Managed Google Play enterprise bound (bindStatus=boundAndValidated, owner mdms@)
- [x] Apple MDM Push Cert uploaded (Apple ID mdms@cascadestucson.com, serial 16FA0CAED8EEB74F, expires 2027-04-20). Renewal reminder task #9.
- [x] CSCNet Wi-Fi password vaulted (`clients/cascades-tucson/wifi-cscnet.sops.yaml`)
- [x] Entra group `Cascades - Shared Phones` + Android enrollment profile `CSC - Android Shared Phones` (token MVDVVDMPSHYJAGDAJOCN, expires 2026-06-22, linked to the Entra group)
- [ ] **NEXT:** Android compliance policy (Phase B-1 in progress — walkthrough ready, Howard to execute)
- [ ] Android configuration profile (CSCNet Wi-Fi + dedicated-device restrictions)
- [ ] Required apps from Managed Play (Company Portal, Authenticator, Edge, Teams)
- [ ] ALIS web shortcut (https://cascadestucson.alisonline.com/Login)
- [ ] Microsoft Shared Device Mode app-configuration policy (for Authenticator/Teams)
- [ ] Test-enroll first Samsung A15, validate, then roll the remaining 24
- [ ] Rotate MDMS@ password (post-rollout hygiene, task #8)
- [ ] iPads are on a generic Apple ID currently — bringing them into Intune is low-priority; ABM + DEM deferred until after phones are live
---
## Recent Changes
| Date | By | Change | Status |
|------|-----|--------|--------|
| 2026-04-20 | Howard | Intune MDM rollout - service account MDMS@ + Google Play bind + Apple push cert + Entra group + Android enrollment profile (QR code) all live. Phone policies next session. | IN PROGRESS |
| 2026-04-17 | Howard | Folder redirection validated on DESKTOP-DLTAGOI (Sharon Edwards); GPO `CSC - Folder Redirection (LE)` active | DEPLOYED |
---