Files
claudetools/clients/valleywide/reports/2026-06-29-offboarding-teresa-carpio.md
Mike Swanson 9a6e1157a7 sync: auto-sync from GURU-5070 at 2026-06-29 15:30:34
Author: Mike Swanson
Machine: GURU-5070
Timestamp: 2026-06-29 15:30:34
2026-06-29 15:31:35 -07:00

75 lines
4.3 KiB
Markdown

# Offboarding Lockdown — Teresa Carpio (VWP)
- **Date (UTC):** 2026-06-29
- **Tech:** Mike Swanson (GURU-5070)
- **Reason:** Employee quit unexpectedly — lock out of all access, primarily email.
- **Tenant:** valleywideplastering.com (`5c53ae9f-7071-4248-b834-8685b646450f`)
- **Target:** `teresa@valleywideplastering.com` (objectId `615d8ef9-e3cc-49a8-bd56-19921cafea4e`)
- **Tooling:** remediation-tool skill (ComputerGuru tiered app suite)
## Pre-action state (read-only check — clean)
- Account enabled; created 2023-03-17; last password change 2025-09-04.
- Mailbox: **0 inbox rules**, no forwarding, no hidden rules, no foreign delegates/SendAs.
- Auth methods (3): password, SMS `+1 602-228-3396`, Microsoft Authenticator (iPhone 14 Plus).
- Licenses: M365 Business Premium (no Teams), Flow Free.
- **Directory role: User Administrator** (privileged — unusual for payroll staff).
- Group memberships: Estimating Archive, Office Archive, QB, Valley Wide Plastering.
- Sign-ins (30d interactive): 0 flagged / none non-US. No risky-user/risk detections.
- **Sent/Deleted review (per request):** no exfiltration. Sent = routine internal pay
sheets/orders/estimating to coworkers + legit vendors (henryproducts.com, engagebp.com);
last send 2026-06-29 07:58 MST. Deleted = newsletters/automated notices only (no record
destruction / track-covering).
## Actions taken (confirmed by Mike)
| Action | Result |
|---|---|
| Reset password to random value (permanent) | OK — required JIT elevation (she holds User Admin) |
| Delete SMS auth method (`+1 602-228-3396`) | HTTP 204 |
| Delete Microsoft Authenticator (iPhone 14 Plus) | HTTP 204 |
| Revoke all sign-in sessions | `value: true` |
| Block sign-in (`accountEnabled=false`) | HTTP 204 — verified false |
| Remove User Administrator directory role | HTTP 204 — role now has zero members; user has no roles |
| Verify auth methods | Only `passwordAuthenticationMethod` remains (no MFA) |
Account is **cloud-only** (`onPremisesSyncEnabled: null`) — the on-prem AD account is a separate
identity. New password stored in vault: `clients/valleywide/teresa-m365-offboarded`. License +
mailbox retained for handoff (account disabled, not deleted).
**Billing:** Syncro **#32487** (Emergency offboarding) — 1.0 hr emergency remote billed as `26184`
@ qty 1.5 (prepaid premium); invoice $0.00, block 15.5 → 14.0 hrs.
**Rose access:** could not verify delegate/SendAs — EXO read returns HTTP 401 (Security Investigator
SP lacks Exchange Admin role on this tenant). Earlier breach check showed no foreign delegates.
## [CRITICAL] Cleanup required — human Global Admin action
The password reset JIT-granted **Privileged Authentication Administrator** to the ComputerGuru
Tenant Admin SP (`fccda86c-77ca-4248-b876-b0cdba8605d4`). The script could not auto-remove it:
an app-only SP **cannot remove its own** privileged role ("no privilege to remove self"). Standing
PAA is now on our SP in the VWP tenant and must be removed by a human Global Admin:
> Entra portal → Roles and administrators → Privileged Authentication Administrator →
> remove **ComputerGuru Tenant Admin**. (Assignment id `ikzke6-tKk6E1qsmSeCKE2yozfzKd0hCuHawzbqGBdQ-1`.)
This is a script design flaw (logged to errorlog) — likely also left standing PAA on
**birthbiologic.com** (the 2026-06-08 reset). Worth a fleet sweep.
## Still open
- **On-prem AD `VWP.US`** — disable her personal user. **BLOCKED on VPN** (no route to
192.168.0.25; needs VWP OpenVPN connected). The **`VWP\Payroll`** account she used on the XP
Orders VM is likely *shared* — confirm before disabling.
- Shared mailboxes `payroll@` / `orders@` — rotate / remove her access if delegated.
- VPN (OpenVPN on UDM), RDP/RemoteApp to VWP-QBS, QuickBooks login.
## Handoff (done 2026-06-29)
Granted **`payroll@valleywideplastering.com` FullAccess** on `teresa@` (InheritanceType All,
AutoMapping on) via Exchange Operator — Teresa's mailbox auto-mounts in the payroll Outlook
profile. FullAccess only; no Send-As/Send-on-Behalf. Verified (not inherited, Deny: False).
Documented on Syncro #32487 (public + emailed comment). Note: the **Exchange Operator** SP
IS consented + Exchange-Admin-roled on VWP — the earlier 401 was the *Security Investigator*
SP (different app); gotchas tenant table is stale on VWP.