diff --git a/clients/cascades-tucson/docs/REMAINING-WORK-PLAN.md b/clients/cascades-tucson/docs/REMAINING-WORK-PLAN.md index a4915b0d..4a761a09 100644 --- a/clients/cascades-tucson/docs/REMAINING-WORK-PLAN.md +++ b/clients/cascades-tucson/docs/REMAINING-WORK-PLAN.md @@ -222,6 +222,24 @@ Final lockdown = flip from test scope to real caregivers, one device at a time 2026-04-29, still unbuilt (HIPAA SS164.312(b) gap, includes D:\Homes object-access auditing). - Zeke Huerta: register Authenticator MFA (under MFA-for-all with no method since 7/1). - Megan Hiatt: re-verify the April credential-stuffing remediation held (flagged 6/30). +- **[NEW 2026-07-22] Entra SMS/voice MFA retirement prep** — Microsoft retires native SMS/voice + MFA delivery ([announcement](https://learn.microsoft.com/en-us/entra/identity/authentication/concept-sms-voice-retirement)). + Timeline: **Sep 1, 2026** passkeys auto-enabled + registration nudge for SMS/voice users; + **Feb 1, 2027** Microsoft-provided SMS/voice fully retired (blocking passkey prompt, no opt-out, + all tenants enforced). Action items: + - **Before Sep 1:** Run Microsoft's [SMS/voice usage analyzer script](https://github.com/microsoft/entra-sms-voice-usage-analyzer) + against the Cascades tenant to identify every user still registered for SMS or voice MFA. + - **Retire `SG-MFA-Voice-Call-Scoped-sysadmin`** (`304f941e`) and remove voice-call as a method + for `sysadmin@cascadestucson.com` — switch to Authenticator or passkey before Sep 1. + - **Migrate any admin/director/nurse users still on SMS-only MFA** to Authenticator or passkey. + - **Decision: third-party telecom provider needed?** Probably not for a 45-seat tenant where all + staff can move to Authenticator — but evaluate after the usage scan. If needed, Security Store + providers available Oct 30, 2026. + - **Communicate to Ashley Jensen** that admin/director users will see passkey registration prompts + at MFA sign-in starting Sep 1. + - HIPAA note: passkeys are phishing-resistant (NIST AAL3-capable) — this forced migration + strengthens the 164.312(d) person/entity authentication posture. Break-glass accounts already + planned with FIDO2/YubiKeys (passkey-compatible, no design change needed). --- diff --git a/clients/instrumental-music-center/docs/cloud/IMG_20260721_172248.jpg b/clients/instrumental-music-center/docs/cloud/IMG_20260721_172248.jpg new file mode 100644 index 00000000..3a94451f Binary files /dev/null and b/clients/instrumental-music-center/docs/cloud/IMG_20260721_172248.jpg differ diff --git a/clients/instrumental-music-center/docs/cloud/m365.md b/clients/instrumental-music-center/docs/cloud/m365.md index dc32af27..3502989e 100644 --- a/clients/instrumental-music-center/docs/cloud/m365.md +++ b/clients/instrumental-music-center/docs/cloud/m365.md @@ -1,52 +1,49 @@ # Microsoft 365 ## Tenant Info -- Tenant Name: -- Tenant ID: -- Primary Domain: +- Tenant Name: Instrumental Music Center +- Tenant ID: [unverified - ACG admin access not confirmed] +- Primary Domain: instrumentalmusic.onmicrosoft.com - Admin Portal URL: https://admin.microsoft.com +- ACG Admin Access: [unverified - need to determine if ACG has delegated admin or direct access] + +## Known Accounts + +Role-based M365 accounts from Leslie's records (2026-07-21). Credentials vaulted at +`clients/imc/m365-accounts.sops.yaml`. + +| Account | UPN | Purpose | +|---------|-----|---------| +| MOO | moo@instrumentalmusic.onmicrosoft.com | MOO location (6300 E El Dorado) | +| Management | management@instrumentalmusic.onmicrosoft.com | Management role | +| Remote | remote@instrumentalmusic.onmicrosoft.com | Remote access | +| Repair | repair@instrumentalmusic.onmicrosoft.com | Repair department | +| Retail | retail@instrumentalmusic.onmicrosoft.com | Retail/sales | + +Leslie wants one of these existing licenses assigned to the edservices4 workstation +(ticket #32569). Which account and license type TBD -- need to verify ACG's access +to the tenant first. + +## Mixed Identity Model + +IMC uses a mixed Google Workspace / Microsoft 365 identity model. Different users are +on different platforms. When configuring a new user, confirm with Leslie which platform +their mailbox lives on before setting up Outlook vs Gmail. ## Licensing | License Type | Quantity | Assigned | Available | |--------------------------|----------|----------|-----------| -| Microsoft 365 Business Basic | | | | -| Microsoft 365 Business Standard | | | | -| Microsoft 365 Business Premium | | | | -| Exchange Online Plan 1/2 | | | | -| Other | | | | +| [unverified] | | | | ## Exchange Online -- Mail Domain(s): -- MX Record Points To: -- SPF Record: -- DKIM Enabled: Yes/No -- DMARC Policy: -- Shared Mailboxes: -- Distribution Groups: -- Mail Flow Rules: Yes/No (describe below) - -## SharePoint / OneDrive -- SharePoint Sites: -- External Sharing: Enabled/Disabled -- OneDrive Storage Limit: - -## Teams -- Teams Phone System: Yes/No -- Calling Plan / Direct Routing: -- Auto Attendant: +- Mail Domain(s): [unverified - may use @imc-az.com or custom domain] +- MX Record Points To: [unverified] ## Entra ID (Azure AD) -- Hybrid Joined: Yes/No -- Azure AD Connect Server: -- Sync Schedule: -- Password Hash Sync: Yes/No -- MFA Enforced: Yes/No -- Conditional Access Policies: - -## Security -- Defender for Office 365: Yes/No -- Safe Links: Yes/No -- Safe Attachments: Yes/No -- Audit Log Retention: +- Hybrid Joined: No (on-prem AD is imc.local, no Azure AD Connect observed) +- MFA Enforced: [unverified] ## Notes +- Photo of Leslie's account spreadsheet saved at `docs/cloud/IMG_20260721_172248.jpg` +- The spreadsheet also confirmed USER#=4 for the edservices4 workstation +- Manda was on the M365 side (Outlook configured against M365 mailbox, per 2026-04-28 session) diff --git a/errorlog.md b/errorlog.md index 2aa505dd..4bb92c23 100644 Binary files a/errorlog.md and b/errorlog.md differ diff --git a/wiki/clients/cascades-tucson.md b/wiki/clients/cascades-tucson.md index 21f3bd43..13d7e392 100644 --- a/wiki/clients/cascades-tucson.md +++ b/wiki/clients/cascades-tucson.md @@ -100,7 +100,7 @@ Senior living / assisted living facility in Tucson, AZ (201 N Jessica Ave, 85710 - **Shared mailbox conversions (2026-07-17):** 10 functional/role-based accounts converted to shared mailboxes (accounting@, accountingassistant@, boadmin@, hr@, security@, Training@, medtech@, nurse@, transportation@, fax@). Freed 6x O365_BUSINESS_PREMIUM + 4x EXCHANGE_S_ESSENTIALS licenses. frontdesk@ and memcarereceptionist@ left as licensed user mailboxes (active daily sign-ins). - **On-prem AD domain:** cascades.local | UPN suffix: cascadestucson.com - **MX / mail flow:** Exchange Online (EOP direct MX). SPF: `-all`. DKIM: both M365 selectors published. DMARC: `p=quarantine; pct=100` (verified live 2026-07-15). Reports to `info@cascadestucson.com` (unmonitored). No third-party gateway. -- **MFA:** CA policy "Require MFA for all users" (`7e87a1c7`) enabled. Caregivers excluded from MFA (protected by on-network block + 8h reauth + device restriction). Voice-call MFA disabled tenant-wide; exception: `SG-MFA-Voice-Call-Scoped-sysadmin` (`304f941e`, single member `sysadmin@`). +- **MFA:** CA policy "Require MFA for all users" (`7e87a1c7`) enabled. Caregivers excluded from MFA (protected by on-network block + 8h reauth + device restriction). Voice-call MFA disabled tenant-wide; exception: `SG-MFA-Voice-Call-Scoped-sysadmin` (`304f941e`, single member `sysadmin@`). **[ACTION REQUIRED by Sep 1, 2026]** Microsoft retires native SMS/voice MFA — passkeys auto-enabled Sep 1; SMS/voice fully retired Feb 1, 2027 (blocking, no opt-out). Run usage analyzer, retire the voice-call exception for sysadmin@, migrate any SMS-only users to Authenticator/passkey. See REMAINING-WORK-PLAN.md WS4. - **Entra Connect:** Installed on CS-SERVER 2026-04-25; exited staging 2026-05-14; actively syncing. Sync scope: ONLY `OU=Caregivers`, `OU=Groups`, `OU=Caregiver Devices`. `OU=Administrative` not yet in scope. **Cloud/Graph group adds to `SG-Caregivers` fail (HTTP 400) — all membership writes on CS-SERVER via RMM.** - **Break-glass accounts:** `breakglass1-csc@cascadestucson.com`, `breakglass2-csc@cascadestucson.com`. **Not yet created as of 2026-07-17.** Must exist + FIDO2 keys enrolled before the final CA allow-list flip (WS3). This is the top prerequisite blocking the caregiver lockdown go-live. - **Admin accounts:** @@ -403,6 +403,7 @@ Established 2026-07-09 (Bariffa Sika -> Charity Menle). **Rename, never re-creat - **[SECURITY] Remove standing PAA role from Tenant Admin SP.** Needs Global Admin. Pending Mike. - **[SECURITY] Rotate exposed Synology Cloud Signin Portal credential** (vault commit 1fbc0e1). - **[PENDING] Zeke Huerta MFA (Authenticator) registration.** No registered method since front-desk move (2026-07-01). +- **[ACTION — before Sep 1, 2026] Entra SMS/voice MFA retirement prep.** Run usage analyzer script; retire `SG-MFA-Voice-Call-Scoped-sysadmin` + voice-call method for sysadmin@; migrate any SMS-only users to Authenticator/passkey. Feb 1, 2027 hard cutoff (blocking, no opt-out). Detail: REMAINING-WORK-PLAN.md WS4. - **[PENDING] ASSISTNURSE-PC nurse station kiosk config** (OU move + printers + gpupdate). - **[PENDING] NURSESTATION-PC PRT/SSO verification** (confirm AzureAdPrt: YES + ALIS SSO silent after reboot). - **[PENDING] MEMCARE-STATION rename not applied** (pending reboot on MemCare RECEPTIONIST-PC box, S/N MJ0KQH4R).