sync: auto-sync from HOWARD-HOME at 2026-07-22 09:14:19
Author: Howard Enos Machine: HOWARD-HOME Timestamp: 2026-07-22 09:14:19
This commit is contained in:
@@ -222,6 +222,24 @@ Final lockdown = flip from test scope to real caregivers, one device at a time
|
|||||||
2026-04-29, still unbuilt (HIPAA SS164.312(b) gap, includes D:\Homes object-access auditing).
|
2026-04-29, still unbuilt (HIPAA SS164.312(b) gap, includes D:\Homes object-access auditing).
|
||||||
- Zeke Huerta: register Authenticator MFA (under MFA-for-all with no method since 7/1).
|
- Zeke Huerta: register Authenticator MFA (under MFA-for-all with no method since 7/1).
|
||||||
- Megan Hiatt: re-verify the April credential-stuffing remediation held (flagged 6/30).
|
- Megan Hiatt: re-verify the April credential-stuffing remediation held (flagged 6/30).
|
||||||
|
- **[NEW 2026-07-22] Entra SMS/voice MFA retirement prep** — Microsoft retires native SMS/voice
|
||||||
|
MFA delivery ([announcement](https://learn.microsoft.com/en-us/entra/identity/authentication/concept-sms-voice-retirement)).
|
||||||
|
Timeline: **Sep 1, 2026** passkeys auto-enabled + registration nudge for SMS/voice users;
|
||||||
|
**Feb 1, 2027** Microsoft-provided SMS/voice fully retired (blocking passkey prompt, no opt-out,
|
||||||
|
all tenants enforced). Action items:
|
||||||
|
- **Before Sep 1:** Run Microsoft's [SMS/voice usage analyzer script](https://github.com/microsoft/entra-sms-voice-usage-analyzer)
|
||||||
|
against the Cascades tenant to identify every user still registered for SMS or voice MFA.
|
||||||
|
- **Retire `SG-MFA-Voice-Call-Scoped-sysadmin`** (`304f941e`) and remove voice-call as a method
|
||||||
|
for `sysadmin@cascadestucson.com` — switch to Authenticator or passkey before Sep 1.
|
||||||
|
- **Migrate any admin/director/nurse users still on SMS-only MFA** to Authenticator or passkey.
|
||||||
|
- **Decision: third-party telecom provider needed?** Probably not for a 45-seat tenant where all
|
||||||
|
staff can move to Authenticator — but evaluate after the usage scan. If needed, Security Store
|
||||||
|
providers available Oct 30, 2026.
|
||||||
|
- **Communicate to Ashley Jensen** that admin/director users will see passkey registration prompts
|
||||||
|
at MFA sign-in starting Sep 1.
|
||||||
|
- HIPAA note: passkeys are phishing-resistant (NIST AAL3-capable) — this forced migration
|
||||||
|
strengthens the 164.312(d) person/entity authentication posture. Break-glass accounts already
|
||||||
|
planned with FIDO2/YubiKeys (passkey-compatible, no design change needed).
|
||||||
|
|
||||||
---
|
---
|
||||||
|
|
||||||
|
|||||||
Binary file not shown.
|
After Width: | Height: | Size: 733 KiB |
@@ -1,52 +1,49 @@
|
|||||||
# Microsoft 365
|
# Microsoft 365
|
||||||
|
|
||||||
## Tenant Info
|
## Tenant Info
|
||||||
- Tenant Name:
|
- Tenant Name: Instrumental Music Center
|
||||||
- Tenant ID:
|
- Tenant ID: [unverified - ACG admin access not confirmed]
|
||||||
- Primary Domain:
|
- Primary Domain: instrumentalmusic.onmicrosoft.com
|
||||||
- Admin Portal URL: https://admin.microsoft.com
|
- Admin Portal URL: https://admin.microsoft.com
|
||||||
|
- ACG Admin Access: [unverified - need to determine if ACG has delegated admin or direct access]
|
||||||
|
|
||||||
|
## Known Accounts
|
||||||
|
|
||||||
|
Role-based M365 accounts from Leslie's records (2026-07-21). Credentials vaulted at
|
||||||
|
`clients/imc/m365-accounts.sops.yaml`.
|
||||||
|
|
||||||
|
| Account | UPN | Purpose |
|
||||||
|
|---------|-----|---------|
|
||||||
|
| MOO | moo@instrumentalmusic.onmicrosoft.com | MOO location (6300 E El Dorado) |
|
||||||
|
| Management | management@instrumentalmusic.onmicrosoft.com | Management role |
|
||||||
|
| Remote | remote@instrumentalmusic.onmicrosoft.com | Remote access |
|
||||||
|
| Repair | repair@instrumentalmusic.onmicrosoft.com | Repair department |
|
||||||
|
| Retail | retail@instrumentalmusic.onmicrosoft.com | Retail/sales |
|
||||||
|
|
||||||
|
Leslie wants one of these existing licenses assigned to the edservices4 workstation
|
||||||
|
(ticket #32569). Which account and license type TBD -- need to verify ACG's access
|
||||||
|
to the tenant first.
|
||||||
|
|
||||||
|
## Mixed Identity Model
|
||||||
|
|
||||||
|
IMC uses a mixed Google Workspace / Microsoft 365 identity model. Different users are
|
||||||
|
on different platforms. When configuring a new user, confirm with Leslie which platform
|
||||||
|
their mailbox lives on before setting up Outlook vs Gmail.
|
||||||
|
|
||||||
## Licensing
|
## Licensing
|
||||||
| License Type | Quantity | Assigned | Available |
|
| License Type | Quantity | Assigned | Available |
|
||||||
|--------------------------|----------|----------|-----------|
|
|--------------------------|----------|----------|-----------|
|
||||||
| Microsoft 365 Business Basic | | | |
|
| [unverified] | | | |
|
||||||
| Microsoft 365 Business Standard | | | |
|
|
||||||
| Microsoft 365 Business Premium | | | |
|
|
||||||
| Exchange Online Plan 1/2 | | | |
|
|
||||||
| Other | | | |
|
|
||||||
|
|
||||||
## Exchange Online
|
## Exchange Online
|
||||||
- Mail Domain(s):
|
- Mail Domain(s): [unverified - may use @imc-az.com or custom domain]
|
||||||
- MX Record Points To:
|
- MX Record Points To: [unverified]
|
||||||
- SPF Record:
|
|
||||||
- DKIM Enabled: Yes/No
|
|
||||||
- DMARC Policy:
|
|
||||||
- Shared Mailboxes:
|
|
||||||
- Distribution Groups:
|
|
||||||
- Mail Flow Rules: Yes/No (describe below)
|
|
||||||
|
|
||||||
## SharePoint / OneDrive
|
|
||||||
- SharePoint Sites:
|
|
||||||
- External Sharing: Enabled/Disabled
|
|
||||||
- OneDrive Storage Limit:
|
|
||||||
|
|
||||||
## Teams
|
|
||||||
- Teams Phone System: Yes/No
|
|
||||||
- Calling Plan / Direct Routing:
|
|
||||||
- Auto Attendant:
|
|
||||||
|
|
||||||
## Entra ID (Azure AD)
|
## Entra ID (Azure AD)
|
||||||
- Hybrid Joined: Yes/No
|
- Hybrid Joined: No (on-prem AD is imc.local, no Azure AD Connect observed)
|
||||||
- Azure AD Connect Server:
|
- MFA Enforced: [unverified]
|
||||||
- Sync Schedule:
|
|
||||||
- Password Hash Sync: Yes/No
|
|
||||||
- MFA Enforced: Yes/No
|
|
||||||
- Conditional Access Policies:
|
|
||||||
|
|
||||||
## Security
|
|
||||||
- Defender for Office 365: Yes/No
|
|
||||||
- Safe Links: Yes/No
|
|
||||||
- Safe Attachments: Yes/No
|
|
||||||
- Audit Log Retention:
|
|
||||||
|
|
||||||
## Notes
|
## Notes
|
||||||
|
- Photo of Leslie's account spreadsheet saved at `docs/cloud/IMG_20260721_172248.jpg`
|
||||||
|
- The spreadsheet also confirmed USER#=4 for the edservices4 workstation
|
||||||
|
- Manda was on the M365 side (Outlook configured against M365 mailbox, per 2026-04-28 session)
|
||||||
|
|||||||
BIN
errorlog.md
BIN
errorlog.md
Binary file not shown.
@@ -100,7 +100,7 @@ Senior living / assisted living facility in Tucson, AZ (201 N Jessica Ave, 85710
|
|||||||
- **Shared mailbox conversions (2026-07-17):** 10 functional/role-based accounts converted to shared mailboxes (accounting@, accountingassistant@, boadmin@, hr@, security@, Training@, medtech@, nurse@, transportation@, fax@). Freed 6x O365_BUSINESS_PREMIUM + 4x EXCHANGE_S_ESSENTIALS licenses. frontdesk@ and memcarereceptionist@ left as licensed user mailboxes (active daily sign-ins).
|
- **Shared mailbox conversions (2026-07-17):** 10 functional/role-based accounts converted to shared mailboxes (accounting@, accountingassistant@, boadmin@, hr@, security@, Training@, medtech@, nurse@, transportation@, fax@). Freed 6x O365_BUSINESS_PREMIUM + 4x EXCHANGE_S_ESSENTIALS licenses. frontdesk@ and memcarereceptionist@ left as licensed user mailboxes (active daily sign-ins).
|
||||||
- **On-prem AD domain:** cascades.local | UPN suffix: cascadestucson.com
|
- **On-prem AD domain:** cascades.local | UPN suffix: cascadestucson.com
|
||||||
- **MX / mail flow:** Exchange Online (EOP direct MX). SPF: `-all`. DKIM: both M365 selectors published. DMARC: `p=quarantine; pct=100` (verified live 2026-07-15). Reports to `info@cascadestucson.com` (unmonitored). No third-party gateway.
|
- **MX / mail flow:** Exchange Online (EOP direct MX). SPF: `-all`. DKIM: both M365 selectors published. DMARC: `p=quarantine; pct=100` (verified live 2026-07-15). Reports to `info@cascadestucson.com` (unmonitored). No third-party gateway.
|
||||||
- **MFA:** CA policy "Require MFA for all users" (`7e87a1c7`) enabled. Caregivers excluded from MFA (protected by on-network block + 8h reauth + device restriction). Voice-call MFA disabled tenant-wide; exception: `SG-MFA-Voice-Call-Scoped-sysadmin` (`304f941e`, single member `sysadmin@`).
|
- **MFA:** CA policy "Require MFA for all users" (`7e87a1c7`) enabled. Caregivers excluded from MFA (protected by on-network block + 8h reauth + device restriction). Voice-call MFA disabled tenant-wide; exception: `SG-MFA-Voice-Call-Scoped-sysadmin` (`304f941e`, single member `sysadmin@`). **[ACTION REQUIRED by Sep 1, 2026]** Microsoft retires native SMS/voice MFA — passkeys auto-enabled Sep 1; SMS/voice fully retired Feb 1, 2027 (blocking, no opt-out). Run usage analyzer, retire the voice-call exception for sysadmin@, migrate any SMS-only users to Authenticator/passkey. See REMAINING-WORK-PLAN.md WS4.
|
||||||
- **Entra Connect:** Installed on CS-SERVER 2026-04-25; exited staging 2026-05-14; actively syncing. Sync scope: ONLY `OU=Caregivers`, `OU=Groups`, `OU=Caregiver Devices`. `OU=Administrative` not yet in scope. **Cloud/Graph group adds to `SG-Caregivers` fail (HTTP 400) — all membership writes on CS-SERVER via RMM.**
|
- **Entra Connect:** Installed on CS-SERVER 2026-04-25; exited staging 2026-05-14; actively syncing. Sync scope: ONLY `OU=Caregivers`, `OU=Groups`, `OU=Caregiver Devices`. `OU=Administrative` not yet in scope. **Cloud/Graph group adds to `SG-Caregivers` fail (HTTP 400) — all membership writes on CS-SERVER via RMM.**
|
||||||
- **Break-glass accounts:** `breakglass1-csc@cascadestucson.com`, `breakglass2-csc@cascadestucson.com`. **Not yet created as of 2026-07-17.** Must exist + FIDO2 keys enrolled before the final CA allow-list flip (WS3). This is the top prerequisite blocking the caregiver lockdown go-live.
|
- **Break-glass accounts:** `breakglass1-csc@cascadestucson.com`, `breakglass2-csc@cascadestucson.com`. **Not yet created as of 2026-07-17.** Must exist + FIDO2 keys enrolled before the final CA allow-list flip (WS3). This is the top prerequisite blocking the caregiver lockdown go-live.
|
||||||
- **Admin accounts:**
|
- **Admin accounts:**
|
||||||
@@ -403,6 +403,7 @@ Established 2026-07-09 (Bariffa Sika -> Charity Menle). **Rename, never re-creat
|
|||||||
- **[SECURITY] Remove standing PAA role from Tenant Admin SP.** Needs Global Admin. Pending Mike.
|
- **[SECURITY] Remove standing PAA role from Tenant Admin SP.** Needs Global Admin. Pending Mike.
|
||||||
- **[SECURITY] Rotate exposed Synology Cloud Signin Portal credential** (vault commit 1fbc0e1).
|
- **[SECURITY] Rotate exposed Synology Cloud Signin Portal credential** (vault commit 1fbc0e1).
|
||||||
- **[PENDING] Zeke Huerta MFA (Authenticator) registration.** No registered method since front-desk move (2026-07-01).
|
- **[PENDING] Zeke Huerta MFA (Authenticator) registration.** No registered method since front-desk move (2026-07-01).
|
||||||
|
- **[ACTION — before Sep 1, 2026] Entra SMS/voice MFA retirement prep.** Run usage analyzer script; retire `SG-MFA-Voice-Call-Scoped-sysadmin` + voice-call method for sysadmin@; migrate any SMS-only users to Authenticator/passkey. Feb 1, 2027 hard cutoff (blocking, no opt-out). Detail: REMAINING-WORK-PLAN.md WS4.
|
||||||
- **[PENDING] ASSISTNURSE-PC nurse station kiosk config** (OU move + printers + gpupdate).
|
- **[PENDING] ASSISTNURSE-PC nurse station kiosk config** (OU move + printers + gpupdate).
|
||||||
- **[PENDING] NURSESTATION-PC PRT/SSO verification** (confirm AzureAdPrt: YES + ALIS SSO silent after reboot).
|
- **[PENDING] NURSESTATION-PC PRT/SSO verification** (confirm AzureAdPrt: YES + ALIS SSO silent after reboot).
|
||||||
- **[PENDING] MEMCARE-STATION rename not applied** (pending reboot on MemCare RECEPTIONIST-PC box, S/N MJ0KQH4R).
|
- **[PENDING] MEMCARE-STATION rename not applied** (pending reboot on MemCare RECEPTIONIST-PC box, S/N MJ0KQH4R).
|
||||||
|
|||||||
Reference in New Issue
Block a user