sync: auto-sync from HOWARD-HOME at 2026-07-22 09:14:19

Author: Howard Enos
Machine: HOWARD-HOME
Timestamp: 2026-07-22 09:14:19
This commit is contained in:
2026-07-22 09:14:53 -07:00
parent 8fb2270b27
commit 9080ac68ab
5 changed files with 55 additions and 39 deletions

View File

@@ -222,6 +222,24 @@ Final lockdown = flip from test scope to real caregivers, one device at a time
2026-04-29, still unbuilt (HIPAA SS164.312(b) gap, includes D:\Homes object-access auditing). 2026-04-29, still unbuilt (HIPAA SS164.312(b) gap, includes D:\Homes object-access auditing).
- Zeke Huerta: register Authenticator MFA (under MFA-for-all with no method since 7/1). - Zeke Huerta: register Authenticator MFA (under MFA-for-all with no method since 7/1).
- Megan Hiatt: re-verify the April credential-stuffing remediation held (flagged 6/30). - Megan Hiatt: re-verify the April credential-stuffing remediation held (flagged 6/30).
- **[NEW 2026-07-22] Entra SMS/voice MFA retirement prep** — Microsoft retires native SMS/voice
MFA delivery ([announcement](https://learn.microsoft.com/en-us/entra/identity/authentication/concept-sms-voice-retirement)).
Timeline: **Sep 1, 2026** passkeys auto-enabled + registration nudge for SMS/voice users;
**Feb 1, 2027** Microsoft-provided SMS/voice fully retired (blocking passkey prompt, no opt-out,
all tenants enforced). Action items:
- **Before Sep 1:** Run Microsoft's [SMS/voice usage analyzer script](https://github.com/microsoft/entra-sms-voice-usage-analyzer)
against the Cascades tenant to identify every user still registered for SMS or voice MFA.
- **Retire `SG-MFA-Voice-Call-Scoped-sysadmin`** (`304f941e`) and remove voice-call as a method
for `sysadmin@cascadestucson.com` — switch to Authenticator or passkey before Sep 1.
- **Migrate any admin/director/nurse users still on SMS-only MFA** to Authenticator or passkey.
- **Decision: third-party telecom provider needed?** Probably not for a 45-seat tenant where all
staff can move to Authenticator — but evaluate after the usage scan. If needed, Security Store
providers available Oct 30, 2026.
- **Communicate to Ashley Jensen** that admin/director users will see passkey registration prompts
at MFA sign-in starting Sep 1.
- HIPAA note: passkeys are phishing-resistant (NIST AAL3-capable) — this forced migration
strengthens the 164.312(d) person/entity authentication posture. Break-glass accounts already
planned with FIDO2/YubiKeys (passkey-compatible, no design change needed).
--- ---

Binary file not shown.

After

Width:  |  Height:  |  Size: 733 KiB

View File

@@ -1,52 +1,49 @@
# Microsoft 365 # Microsoft 365
## Tenant Info ## Tenant Info
- Tenant Name: - Tenant Name: Instrumental Music Center
- Tenant ID: - Tenant ID: [unverified - ACG admin access not confirmed]
- Primary Domain: - Primary Domain: instrumentalmusic.onmicrosoft.com
- Admin Portal URL: https://admin.microsoft.com - Admin Portal URL: https://admin.microsoft.com
- ACG Admin Access: [unverified - need to determine if ACG has delegated admin or direct access]
## Known Accounts
Role-based M365 accounts from Leslie's records (2026-07-21). Credentials vaulted at
`clients/imc/m365-accounts.sops.yaml`.
| Account | UPN | Purpose |
|---------|-----|---------|
| MOO | moo@instrumentalmusic.onmicrosoft.com | MOO location (6300 E El Dorado) |
| Management | management@instrumentalmusic.onmicrosoft.com | Management role |
| Remote | remote@instrumentalmusic.onmicrosoft.com | Remote access |
| Repair | repair@instrumentalmusic.onmicrosoft.com | Repair department |
| Retail | retail@instrumentalmusic.onmicrosoft.com | Retail/sales |
Leslie wants one of these existing licenses assigned to the edservices4 workstation
(ticket #32569). Which account and license type TBD -- need to verify ACG's access
to the tenant first.
## Mixed Identity Model
IMC uses a mixed Google Workspace / Microsoft 365 identity model. Different users are
on different platforms. When configuring a new user, confirm with Leslie which platform
their mailbox lives on before setting up Outlook vs Gmail.
## Licensing ## Licensing
| License Type | Quantity | Assigned | Available | | License Type | Quantity | Assigned | Available |
|--------------------------|----------|----------|-----------| |--------------------------|----------|----------|-----------|
| Microsoft 365 Business Basic | | | | | [unverified] | | | |
| Microsoft 365 Business Standard | | | |
| Microsoft 365 Business Premium | | | |
| Exchange Online Plan 1/2 | | | |
| Other | | | |
## Exchange Online ## Exchange Online
- Mail Domain(s): - Mail Domain(s): [unverified - may use @imc-az.com or custom domain]
- MX Record Points To: - MX Record Points To: [unverified]
- SPF Record:
- DKIM Enabled: Yes/No
- DMARC Policy:
- Shared Mailboxes:
- Distribution Groups:
- Mail Flow Rules: Yes/No (describe below)
## SharePoint / OneDrive
- SharePoint Sites:
- External Sharing: Enabled/Disabled
- OneDrive Storage Limit:
## Teams
- Teams Phone System: Yes/No
- Calling Plan / Direct Routing:
- Auto Attendant:
## Entra ID (Azure AD) ## Entra ID (Azure AD)
- Hybrid Joined: Yes/No - Hybrid Joined: No (on-prem AD is imc.local, no Azure AD Connect observed)
- Azure AD Connect Server: - MFA Enforced: [unverified]
- Sync Schedule:
- Password Hash Sync: Yes/No
- MFA Enforced: Yes/No
- Conditional Access Policies:
## Security
- Defender for Office 365: Yes/No
- Safe Links: Yes/No
- Safe Attachments: Yes/No
- Audit Log Retention:
## Notes ## Notes
- Photo of Leslie's account spreadsheet saved at `docs/cloud/IMG_20260721_172248.jpg`
- The spreadsheet also confirmed USER#=4 for the edservices4 workstation
- Manda was on the M365 side (Outlook configured against M365 mailbox, per 2026-04-28 session)

Binary file not shown.

View File

@@ -100,7 +100,7 @@ Senior living / assisted living facility in Tucson, AZ (201 N Jessica Ave, 85710
- **Shared mailbox conversions (2026-07-17):** 10 functional/role-based accounts converted to shared mailboxes (accounting@, accountingassistant@, boadmin@, hr@, security@, Training@, medtech@, nurse@, transportation@, fax@). Freed 6x O365_BUSINESS_PREMIUM + 4x EXCHANGE_S_ESSENTIALS licenses. frontdesk@ and memcarereceptionist@ left as licensed user mailboxes (active daily sign-ins). - **Shared mailbox conversions (2026-07-17):** 10 functional/role-based accounts converted to shared mailboxes (accounting@, accountingassistant@, boadmin@, hr@, security@, Training@, medtech@, nurse@, transportation@, fax@). Freed 6x O365_BUSINESS_PREMIUM + 4x EXCHANGE_S_ESSENTIALS licenses. frontdesk@ and memcarereceptionist@ left as licensed user mailboxes (active daily sign-ins).
- **On-prem AD domain:** cascades.local | UPN suffix: cascadestucson.com - **On-prem AD domain:** cascades.local | UPN suffix: cascadestucson.com
- **MX / mail flow:** Exchange Online (EOP direct MX). SPF: `-all`. DKIM: both M365 selectors published. DMARC: `p=quarantine; pct=100` (verified live 2026-07-15). Reports to `info@cascadestucson.com` (unmonitored). No third-party gateway. - **MX / mail flow:** Exchange Online (EOP direct MX). SPF: `-all`. DKIM: both M365 selectors published. DMARC: `p=quarantine; pct=100` (verified live 2026-07-15). Reports to `info@cascadestucson.com` (unmonitored). No third-party gateway.
- **MFA:** CA policy "Require MFA for all users" (`7e87a1c7`) enabled. Caregivers excluded from MFA (protected by on-network block + 8h reauth + device restriction). Voice-call MFA disabled tenant-wide; exception: `SG-MFA-Voice-Call-Scoped-sysadmin` (`304f941e`, single member `sysadmin@`). - **MFA:** CA policy "Require MFA for all users" (`7e87a1c7`) enabled. Caregivers excluded from MFA (protected by on-network block + 8h reauth + device restriction). Voice-call MFA disabled tenant-wide; exception: `SG-MFA-Voice-Call-Scoped-sysadmin` (`304f941e`, single member `sysadmin@`). **[ACTION REQUIRED by Sep 1, 2026]** Microsoft retires native SMS/voice MFA — passkeys auto-enabled Sep 1; SMS/voice fully retired Feb 1, 2027 (blocking, no opt-out). Run usage analyzer, retire the voice-call exception for sysadmin@, migrate any SMS-only users to Authenticator/passkey. See REMAINING-WORK-PLAN.md WS4.
- **Entra Connect:** Installed on CS-SERVER 2026-04-25; exited staging 2026-05-14; actively syncing. Sync scope: ONLY `OU=Caregivers`, `OU=Groups`, `OU=Caregiver Devices`. `OU=Administrative` not yet in scope. **Cloud/Graph group adds to `SG-Caregivers` fail (HTTP 400) — all membership writes on CS-SERVER via RMM.** - **Entra Connect:** Installed on CS-SERVER 2026-04-25; exited staging 2026-05-14; actively syncing. Sync scope: ONLY `OU=Caregivers`, `OU=Groups`, `OU=Caregiver Devices`. `OU=Administrative` not yet in scope. **Cloud/Graph group adds to `SG-Caregivers` fail (HTTP 400) — all membership writes on CS-SERVER via RMM.**
- **Break-glass accounts:** `breakglass1-csc@cascadestucson.com`, `breakglass2-csc@cascadestucson.com`. **Not yet created as of 2026-07-17.** Must exist + FIDO2 keys enrolled before the final CA allow-list flip (WS3). This is the top prerequisite blocking the caregiver lockdown go-live. - **Break-glass accounts:** `breakglass1-csc@cascadestucson.com`, `breakglass2-csc@cascadestucson.com`. **Not yet created as of 2026-07-17.** Must exist + FIDO2 keys enrolled before the final CA allow-list flip (WS3). This is the top prerequisite blocking the caregiver lockdown go-live.
- **Admin accounts:** - **Admin accounts:**
@@ -403,6 +403,7 @@ Established 2026-07-09 (Bariffa Sika -> Charity Menle). **Rename, never re-creat
- **[SECURITY] Remove standing PAA role from Tenant Admin SP.** Needs Global Admin. Pending Mike. - **[SECURITY] Remove standing PAA role from Tenant Admin SP.** Needs Global Admin. Pending Mike.
- **[SECURITY] Rotate exposed Synology Cloud Signin Portal credential** (vault commit 1fbc0e1). - **[SECURITY] Rotate exposed Synology Cloud Signin Portal credential** (vault commit 1fbc0e1).
- **[PENDING] Zeke Huerta MFA (Authenticator) registration.** No registered method since front-desk move (2026-07-01). - **[PENDING] Zeke Huerta MFA (Authenticator) registration.** No registered method since front-desk move (2026-07-01).
- **[ACTION — before Sep 1, 2026] Entra SMS/voice MFA retirement prep.** Run usage analyzer script; retire `SG-MFA-Voice-Call-Scoped-sysadmin` + voice-call method for sysadmin@; migrate any SMS-only users to Authenticator/passkey. Feb 1, 2027 hard cutoff (blocking, no opt-out). Detail: REMAINING-WORK-PLAN.md WS4.
- **[PENDING] ASSISTNURSE-PC nurse station kiosk config** (OU move + printers + gpupdate). - **[PENDING] ASSISTNURSE-PC nurse station kiosk config** (OU move + printers + gpupdate).
- **[PENDING] NURSESTATION-PC PRT/SSO verification** (confirm AzureAdPrt: YES + ALIS SSO silent after reboot). - **[PENDING] NURSESTATION-PC PRT/SSO verification** (confirm AzureAdPrt: YES + ALIS SSO silent after reboot).
- **[PENDING] MEMCARE-STATION rename not applied** (pending reboot on MemCare RECEPTIONIST-PC box, S/N MJ0KQH4R). - **[PENDING] MEMCARE-STATION rename not applied** (pending reboot on MemCare RECEPTIONIST-PC box, S/N MJ0KQH4R).