3.2 KiB
3.2 KiB
Offboarding Record — Alma Montt
Date: 2026-06-25 · Performed by: Howard Enos (ClaudeTools session) · Authorized by: Howard Enos
Separation type: Termination (no longer with Cascades) · Role: Memory Care Life Enrichment / MC Reception
Runbook: docs/security/termination-procedures.md
Identities handled
- M365 (cloud-only):
Alma.Montt@cascadestucson.com— idb2fb546e-687a-4647-b286-9c8edd3d989f - On-prem AD:
Alma.Montt(was OU=Administrative,OU=Departments,DC=cascades,DC=local — separate object, NOT Entra-synced) - ALIS: N/A — Alma had no ALIS access (Life Enrichment role, not clinical/caregiver; confirmed Howard 2026-06-25)
Actions completed (M365)
| # | Action | Result |
|---|---|---|
| 1 | Revoke active sign-in sessions | HTTP 200 |
| 2 | Block sign-in (accountEnabled=false) |
confirmed false |
| 3 | Reset password (random, vaulted) | OK (via JIT PAA — see follow-up) |
| 4 | Grant Shelby.Trozzi FullAccess + AutoMapping to mailbox |
confirmed (auto-attaches in Shelby's Outlook) |
| 5 | Convert mailbox → SharedMailbox | confirmed (78 MB / 198 items) |
| 6 | Remove Business Premium (SPB) license | confirmed 0 licenses — frees 1 SPB seat |
| 7 | Hide from GAL | confirmed |
| 8 | Remove from SG-SSPR-Eligible |
HTTP 204 |
Actions completed (on-prem AD, CS-SERVER)
Disable-ADAccount Alma.Montt→ Enabled=False- Group memberships stripped → groupCount=0
- Moved to
OU=Excluded-From-Sync,DC=cascades,DC=local
Retention / compliance
- No Litigation Hold applied. Decision (Howard, 2026-06-25): Alma had no PHI / medical-data access in her role, so the 7-yr litigation hold is not required. Mailbox is preserved via shared-mailbox conversion + zero-deletion posture (no mailbox deleted). Revisit only if her PHI-access determination changes.
- Password stored for emergency recovery/audit only: vault
clients/cascades-tucson/alma-montt. Do NOT re-enable without authorization.
Open follow-ups
ALIS staff profile— N/A, no ALIS access (Howard 2026-06-25).- SECURITY — needs Global Admin / portal: the password reset required a JIT elevation of the
ComputerGuru – Tenant Admin service principal to Privileged Authentication Administrator, and
the automatic role removal was blocked by Graph ("removing self from built-in role is not allowed").
The PAA role is still assigned to the SP and must be removed manually in Entra
(Roles & admins → Privileged Authentication Administrator → remove
ComputerGuru - Tenant Admin). Its standing Conditional Access Administrator role is intentional — leave that. - Reconcile: Alma removed from the proposed share rosters (
docs/migration/share-group-roster-proposed-2026-06-25.md) and all other active plans (2026-06-25):docs/servers/active-directory.md,docs/printers.md,docs/cloud/user-account-rollout-plan.md,docs/cloud/p2-staff-candidates.md,PLAN-AND-QUESTIONS-2026-04-24.md,docs/migration/share-access-matrix-2026-04-23.md,docs/migration/scripts/phase2-print-server.ps1. Dated April/May questionnaires, CSVs, reports, and the archived plan left as historical record.