# Dataforth — New Hire Account: Delfina Lopez (AD + M365) ## User - **Executed by:** ClaudeTools Discord Bot (GURU-BEAST-ROG) - **Requested by:** Winter Williams (@winterguru, via Discord) - tech - **Role:** automation (acting on the requester's behalf) ## Session Summary Winter requested a new Microsoft account for Dataforth new hire Delfina Lopez (DLopez@dataforth.com) via the Discord bot (thread 1523817544211894402). Because Dataforth is a hybrid environment (on-prem AD `INTRANET` synced to Entra via Azure AD Connect), the account was created on-prem rather than cloud-only. Mike confirmed the approach mid-thread: use an existing license seat and model the account on Kellyn Wackerly. Recon via GuruRMM on AD1 established Kellyn's profile: `OU=Azure_Users` (a synced OU), UPN suffix `dataforth.com`, single group `RDWeb-Users`, no department. Confirmed `dlopez` sAMAccountName and the DLopez@dataforth.com UPN were both free. Created `INTRANET\dlopez` (CN=Delfina Lopez) in OU=Azure_Users on AD1 with UPN/mail DLopez@dataforth.com, added to RDWeb-Users, enabled, ChangePasswordAtLogon=true. Discovered Azure AD Connect runs on AD1 itself (ADSync service present) and triggered a delta sync in the same dispatch — result Success. User appeared in Entra (object id f2085a84-76f5-4131-b602-6fb7daca2c5b, onPremisesSyncEnabled=true) within ~2 minutes. On the M365 side (Graph, client-credentials via the Dataforth Claude-Code-M365 app): set usageLocation=US, then assigned Microsoft 365 Business Standard (SKU f245ecc8-75af-4f8e-b61f-27d8114de5f3 / O365_BUSINESS_PREMIUM) — same SKU as Kellyn — from the existing pool (was 39/50 used, now 40/50; no purchase). Mail attribute populated; EXO mailbox provisioning follows automatically. Winter supplied the associated Syncro ticket #32505 ("Microsoft Access/Log-in request, recent hire.", Dataforth Corp, id 113548034). Per her direction: full work detail posted as a PRIVATE (hidden) note, a PUBLIC note posted with only username + temp password + recommendation to change it after first login, and the ticket set to Resolved. Both comments posted with do_not_email=true (no customer email sent) — flagged to Winter in the thread in case she wants the credentials note emailed. ## Key Decisions - **On-prem-first creation, not cloud-only:** tenant is AAD-Connect synced (`Synced with AD. Domain INTRANET.` per vault; wiki confirms OU=SyncedUsers + OU=Azure_Users sync scope). A cloud-only user would have diverged from the environment's identity model. - **Modeled on Kellyn Wackerly** (Mike's instruction): same OU (Azure_Users), same group (RDWeb-Users), same license SKU (Business Standard). - **SKU disambiguation:** wiki says "50x Business Premium" but the live SKU `O365_BUSINESS_PREMIUM` (f245ecc8) is the legacy part number for **Microsoft 365 Business Standard** — distinct from the 5-seat `SPB` (true Business Premium) SKU. Kellyn holds f245ecc8, so Delfina got f245ecc8. - **Password not stored in the private ticket note** — but per Winter's explicit direction the temp password IS in the public ticket note (credential handoff to the customer via portal). Comments posted without email; offered to email on request. - **usageLocation set before license** (Graph requires it); first assignLicense attempt raced directory replication ("invalid usage location") — resolved with a 10s-backoff retry, no duplicate assignment. ## Problems Encountered - **assignLicense 400 "invalid usage location"** immediately after the usageLocation PATCH (HTTP 204) — Graph replication lag. Retried after 10s: success. License verified present on the user afterward. - **License list on the user lagged too:** immediately after a successful assignLicense POST, `assignedLicenses` still read `[]`; a re-fetch ~20s later showed the SKU. Do not re-POST on an empty read-back — verify with a delayed GET. - **Bash `UID` is readonly** in Git Bash — a script variable named `UID` failed; renamed to `DUID`. ## Configuration Changes - Dataforth AD (AD1): new user object `CN=Delfina Lopez,OU=Azure_Users,DC=intranet,DC=dataforth,DC=com` (sam `dlopez`, UPN/mail `DLopez@dataforth.com`, enabled, change-password-at-logon), member of `RDWeb-Users`. - Dataforth Entra tenant: user synced (id `f2085a84-76f5-4131-b602-6fb7daca2c5b`), usageLocation US, license f245ecc8 (M365 Business Standard) assigned. - Syncro #32505: private work note (comment 422441082), public credentials note (comment 422441088), status -> Resolved. - No repo files changed other than this session log + bot activity log. ## Credentials & Secrets - **Delfina Lopez temp password:** `Mesa-Willow-8264!` — must change at first domain logon (AD flag set). Also posted in the public note on Syncro #32505 per Winter. Not vaulted (one-time temp credential, forced rotation on first use). - Vault paths read (values not recorded here): `clients/dataforth/m365.sops.yaml` (tenant admin + Claude-Code-M365 Entra app), `clients/dataforth/ad1.sops.yaml`, `infrastructure/gururmm-server.sops.yaml` (RMM API). ## Infrastructure & Servers - AD1 = 192.168.0.27 / AD1.intranet.dataforth.com — primary DC; **hosts Azure AD Connect (ADSync service)** — confirmed live this session; delta sync via `Start-ADSyncSyncCycle -PolicyType Delta` works from an RMM dispatch. - GuruRMM agent AD1: bf7bc5ee-4167-4a62-912a-c88b11a5943d (verified live this session). - Dataforth tenant id: 7dfa3ce8-c496-4b51-ab8d-bd3dcd78b584. - License pool after this session: O365_BUSINESS_PREMIUM (Business Standard) 40/50 used; SPB 4/5; EXCHANGESTANDARD 5/19. ## Commands & Outputs - RMM recon (cmd 2b07a028): Kellyn DN `CN=Kellyn Wackerly,OU=Azure_Users,...`, groups RDWeb-Users only; forest UPN suffix `dataforth.com`; dlopez free. - RMM create (cmd 0d4972a3): New-ADUser + Add-ADGroupMember + Start-ADSyncSyncCycle → `SYNC TRIGGERED: Success`, exit 0. - Graph: PATCH usageLocation (204) → assignLicense (retry once) → verified `skus:["f245ecc8-..."]`, `mail: DLopez@dataforth.com`. - Syncro: POST /tickets/113548034/comment ×2 (ids 422441082 hidden, 422441088 public), PUT status Resolved. ## Pending / Incomplete Tasks - EXO mailbox provisioning completes automatically (minutes) — no action expected; verify only if the user reports no mailbox. - Public credentials note was NOT emailed to the customer (do_not_email=true on both comments). Winter to say if she wants it emailed. - Note: AD "change password at first logon" does not force a change on cloud-only sign-ins (flag doesn't sync by default) — hence the written recommendation in the public note. ## Reference Information - Syncro ticket #32505 (id 113548034): https://computerguru.syncromsp.com/tickets/113548034 - Discord thread: 1523817544211894402 (#tech-department) - Requesters: Winter (opened thread), Mike (license/template decision) - Entra user object: f2085a84-76f5-4131-b602-6fb7daca2c5b - Bot alerts posted: RMM dispatch (#dev-alerts), Syncro resolve (#bot-alerts)