Author: Mike Swanson Machine: Mikes-MacBook-Air.local Timestamp: 2026-06-06 11:32:15
9.8 KiB
Gonzvar Tax Services - Onboarding Diagnostic Summary
Date: 2026-06-06 Diagnostics Run: All 6 enrolled machines Client: Gonzvar Tax Services Project Key: gonzvar
IMPORTANT CORRECTION (2026-06-06)
Diagnostic Probe Bug Discovered: Initial diagnostics reported "9 disk errors" on GTS-W0, triggering a CRITICAL finding for failing drive. This was a FALSE POSITIVE.
- The "disk errors" are actually benign VBS (Virtualization-Based Security) boot messages
- Event ID 153 from "Microsoft-Windows-Kernel-Boot" (not disk errors)
- Drive health verified as HEALTHY via direct query
- NO drive replacement needed
- Probe script needs update to filter Event ID 153 by source
- This bug likely affects all Windows 11 machines with VBS enabled
- See
GTS-W0-DISK-ANALYSIS.mdfor full investigation
Revised GTS-W0 Status: Still RED due to firewall/RDP issues, but drive is healthy.
Executive Summary
Complete security and health diagnostics performed on all 6 Gonzvar machines (3 workstations, 1 personal workstation, 2 servers). 3 machines received RED grades requiring immediate attention, 3 machines received AMBER grades requiring scheduled maintenance.
Critical Findings Across Fleet:
- Firewall disabled on multiple machines (all profiles OFF)
- RDP without NLA on multiple machines (pre-auth vulnerability)
- Failing hard drive on GTS-W0 (9 disk errors in 14 days)
- Multiple pending updates across all machines
- BitLocker not enabled on several machines
Machine-by-Machine Results
1. GTS-W0 (Workstation) - RED
Grade: RED
Findings: 3 critical / 4 warning / 14 info
OS: Windows 11 Pro for Workstations (build 26200)
Baseline: GTS-W0-20260606T180736.md
CRITICAL Issues:
-
All firewalls disabled (Domain, Private, Public)
- Exposes machine to lateral movement and inbound attacks
- Action: Re-enable all firewall profiles immediately
-
RDP enabled WITHOUT Network Level Authentication
- Vulnerable to pre-auth exploits and brute force
- Action: Enable NLA or disable RDP; restrict to VPN/allow-listed IPs
-
Recurring stability events - 9 DISK ERRORS in 14 daysFALSE POSITIVE - CORRECTED- ANALYSIS UPDATE 2026-06-06: The "9 disk errors" are NOT disk errors
- All 9 events are Event ID 153 from "Microsoft-Windows-Kernel-Boot" (VBS enabled messages)
- These are informational boot logs, not hardware failures
- Drive is HEALTHY - Kingston NVMe confirmed OK via direct query
- Diagnostic probe bug: Event ID 153 query needs source filtering
- See
GTS-W0-DISK-ANALYSIS.mdfor full investigation - NO DRIVE REPLACEMENT NEEDED
- Actual stability concern: 2 unexpected shutdowns (Event ID 41) - investigate separately
WARNING Issues:
- BitLocker not enabled (OS volume unencrypted)
- 1 pending Windows update
- Reboot pending
- 4 auto-start services not running (including Group Policy Client)
Action Priority: IMMEDIATE - Data at risk from failing drive
2. GTS-W1 (Workstation) - AMBER
Grade: AMBER
Findings: 0 critical / 4 warning / 16 info
OS: Windows 11 Pro for Workstations (build 26200)
Baseline: GTS-W1-20260606T180908.md
WARNING Issues:
- Defender tamper protection OFF
- 2 pending Windows updates
- Reboot pending
- 3 auto-start services not running
Positive:
- BitLocker enabled with TPM + recovery password
- All firewalls enabled
- Defender active and current
- No stability events
Action Priority: Moderate - Schedule maintenance window for updates/reboot
3. GTS-W2 (Workstation) - AMBER
Grade: AMBER
Findings: 0 critical / 7 warning / 16 info
OS: Windows 11 Pro for Workstations (build 26200)
Baseline: GTS-W2-20260606T181016.md
WARNING Issues:
- 7 warnings total (needs detailed review)
- Likely includes: pending updates, services, stability events
Action Priority: Moderate - Review full baseline for specifics
4. GTS-PEDRO-H (Personal Workstation) - AMBER
Grade: AMBER
Findings: 0 critical / 5 warning / 13 info
OS: Windows 11 (build 26200)
Baseline: GTS-PEDRO-H-20260606T181113.md
WARNING Issues:
- 5 warnings (needs detailed review)
Action Priority: Moderate - Personal workstation, lower business priority
5. GTS-SVR25 (Server) - RED
Grade: RED
Findings: 3 critical / 4 warning / 14 info / 1 unknown
OS: Windows 11 (build 26100)
Baseline: GTS-SVR25-20260606T181205.md
CRITICAL Issues:
- 3 critical findings (needs full baseline review)
- Likely includes: firewall, RDP, or encryption issues
- 1 unknown check (probe failed to run)
Action Priority: IMMEDIATE - Production server with critical security issues
6. SERVER (Legacy Server) - RED
Grade: RED
Findings: 3 critical / 6 warning / 12 info / 1 unknown
OS: Windows 10 (build 17763) - Windows Server 2019
Baseline: SERVER-20260606T181304.md
CRITICAL Issues:
- 3 critical findings (needs full baseline review)
- Older Windows 10 base (Server 2019)
- 6 warnings + 1 unknown check
- Likely includes: firewall, RDP, or encryption issues
Action Priority: IMMEDIATE - Production server with critical security issues
Fleet-Wide Observations
Security Concerns
- Firewall disabled on multiple machines - widespread configuration issue
- RDP without NLA on multiple machines - pre-auth vulnerability exposure
- BitLocker inconsistent - some encrypted, some not
- Defender tamper protection disabled on some machines
Health Concerns
- Failing hard drive on GTS-W0 (9 disk errors)
- Pending updates across most/all machines
- Pending reboots on multiple machines
- Group Policy Client stopped on multiple machines (may indicate domain/GPO issues)
Positive Findings
- All machines have Defender active with current signatures
- No competitor/leftover RMM agents detected
- ScreenConnect present on all (expected ACG tooling)
- Recent agent versions (0.6.57)
Recommended Action Plan
Phase 1: IMMEDIATE (Within 24 Hours)
GTS-W0 - Security Hardening:
1. Backup all critical data immediately (failing drive risk) NOT NEEDED - Drive is healthy
2. Run SMART diagnostics COMPLETED - Drive OK
3. Order replacement drive NOT NEEDED
- Enable all firewalls (PowerShell or Group Policy) - CRITICAL
- Enable NLA for RDP or disable RDP entirely - CRITICAL
- Investigate 2 unexpected shutdowns (Event ID 41) - may indicate power issues
GTS-SVR25 & SERVER - Security Hardening:
- Review full baselines for critical findings
- Enable firewalls on all profiles
- Fix RDP (enable NLA or disable)
- Enable BitLocker if not already enabled
- Verify no unauthorized access occurred while exposed
Phase 2: Short-Term (Within 1 Week)
All Machines:
- Install pending Windows updates
- Reboot all machines (clears pending reboot flags)
- Enable Defender tamper protection where disabled
- Enable BitLocker on all unencrypted machines
- Investigate stopped Group Policy Client services
- Run second diagnostic to verify fixes
GTS-W0 Specific:
7. Replace hard drive if SMART shows failures NOT NEEDED - False positive
8. Restore data to new drive NOT NEEDED
7. Re-run diagnostic after probe fix to establish accurate baseline
Phase 3: Ongoing (Within 1 Month)
- Fix diagnostic probe bug - Update Event ID 153 query to exclude VBS boot messages
- Re-run all diagnostics - Get accurate baselines after probe fix (likely affects all Win11 machines)
- Standardize firewall configuration (all profiles enabled)
- Standardize RDP configuration (NLA required or disabled)
- Standardize BitLocker (all OS volumes encrypted)
- Review and clean up auto-start services
- Document baseline configuration standards
- Schedule quarterly re-diagnostics
Technical Details
Diagnostics Performed
- Probe:
onboarding-diagnostic.ps1(70,739 bytes) - Execution: PowerShell as SYSTEM via GuruRMM
- Timeout: 240 seconds per machine
- Output: JSON + Markdown baselines
Checks Performed
- Security: Defender state, AV conflicts, foreign agents, firewall, BitLocker, local admins, patch posture, OS EOL, RDP/NLA, SMBv1, UAC, LAPS
- Health: Disk free %, SMART/disk health, 14-day stability (shutdown/BSOD/disk errors), pending reboot, uptime, failed services, domain channel, time source, battery, backup agent
- Inventory: Hardware (model/serial/CPU/RAM/BIOS/TPM/Secure Boot), OS (edition/build/activation), installed software, network, scheduled tasks, autoruns
Baseline Storage
All baselines stored at:
clients/gonzvar-tax-services/onboarding-baselines/
- GTS-W0-20260606T180736.{json,md}
- GTS-W1-20260606T180908.{json,md}
- GTS-W2-20260606T181016.{json,md}
- GTS-PEDRO-H-20260606T181113.{json,md}
- GTS-SVR25-20260606T181205.{json,md}
- SERVER-20260606T181304.{json,md}
JSON files are immutable snapshots. Markdown files are human-readable reports.
Next Steps
- Review detailed baselines for GTS-SVR25 and SERVER critical findings
- Create remediation scripts for firewall/RDP/BitLocker standardization
- Schedule maintenance window with client for updates/reboots/drive replacement
- Backup GTS-W0 immediately (failing drive)
- Order replacement drive for GTS-W0
- Apply fixes per action plan phases
- Re-run diagnostics after remediation to verify fixes
- Document final baseline configuration standards
Alerts Posted
- Alert sent to #dev-alerts for each critical finding on RED machines
- RMM onboarding alert posted: "Mike onboarded client 'Gonzvar Tax Services' + site 'Main' (INNER-BEAR-6727)"
Report Generated: 2026-06-06 Diagnostics Completed: 2026-06-06 18:13 UTC Total Scan Time: ~6 minutes (all 6 machines) Next Action: Review GTS-SVR25 and SERVER detailed baselines + backup GTS-W0