8f7eaff4-... (NETORGFT2570783, GoDaddy/johnvelez) and dormant ddf3d2c9-... (netorg18235235) — NOT in use
GoDaddy admin
plan@johnvelez.com (John Velez) — ACG has delegate access
Project key
clients/quantumwms
Current Status (2026-06-01)
6/03 license-lapse deadline: RESOLVED. Both firm users are M365 Business Premium licensed AND have activated Office (John + Sheila both signed into Microsoft Office from the Tucson office 2026-05-27). They will not lose Office apps when M365 Personal lapses 2026-06-03.
Mail still on Intermedia (HEX). MX cutover to Exchange Online not yet done; mailboxes in the new tenant are still empty.
Migration remainder pending: PST backups (pre-cutover), MX/mail cutover, CA enforcement, Defender for Business onboarding, DMARC/SPF/DKIM, DNS -> Cloudflare, Exchange Online Plan 1 for personal-domain accounts, GoDaddy/Intermedia cancellation.
Read-only review 2026-06-01 (see clients/quantumwms/reports/2026-06-01-m365-review.md):
john@quantumwms.com hit by a distributed password-spray — 98 failed sign-ins from 98 unique IPs (datacenter/proxy IPv6 + Amsterdam NL malicious-flagged IP + Praha CZ password guess). 0 successful malicious logins — account NOT breached (Entra blocked the IPs; password guesses failed).
Exposure: John is NOT MFA-registered, his initial password is weak/OSINT-guessable, and the protective CA policies (require-MFA, block-non-US) are report-only. Security Defaults is ON but only protects users who have registered MFA — neither John nor Sheila has.
Recommended (not yet done): force-reset John's password; drive both users through MFA registration; enforce CA001 (MFA) + CA003 (block non-US) now (break-glass already excluded).
Microsoft 365 satisfies all FINRA/17a-4 requirements
Microsoft Purview (included in Business Premium) provides WORM-compliant archiving with a CFTC/SEC 17a-4 compliance attestation from Cohasset Associates. The majority of FINRA-registered broker/dealers run on Exchange Online. FINRA has published guidance explicitly endorsing cloud-based recordkeeping.
Action item (BLOCKER)
Sheila has been asked to produce written policy from the Broker/Dealer that explicitly names Intermedia as the required platform. This policy is expected not to exist — the B/D policy will require compliant archiving, not a specific vendor. Resolution expected before meeting 2026-05-27 14:00.
Recommended Architecture: M365 Business Premium + Mailprotector
License Plan
Account
License
Domain
John (firm)
M365 Business Premium
quantumwms.com
Sheila (firm)
M365 Business Premium
quantumwms.com
Sheila (personal)
Exchange Online Plan 1
sheilaperess.com
Others TBD
Exchange Online Plan 1
TBD
What Business Premium provides over Intermedia
Capability
Intermedia Hosted Exchange
M365 Business Premium
Email
Exchange Server (hosted)
Exchange Online (Microsoft cloud)
Exchange CVE exposure
YES — full Server CVE surface
No — Microsoft patches same-day
Spam/malware filtering
Basic
Defender for Office 365 Plan 1 (Safe Links, Safe Attachments)
Frontend filtering
None
Mailprotector (ACG-managed)
MFA enforcement
Manual
Entra ID P1 — Conditional Access
FINRA archiving
Intermedia archiver (extra cost)
Microsoft Purview — included
Desktop Office apps
No
Yes (Word, Excel, Outlook, etc.)
Mobile device management
No
Intune — included
DMARC/DKIM setup
Not managed
ACG-managed during migration
Migration Steps
[DONE] Get consent from John (2026-05-26)
Obtain written B/D compliance policy from Sheila — confirm no Intermedia mandate
Add quantumwms.com as verified domain to johnvelez.com tenant
Migrate existing mail from Intermedia → Exchange Online
Activate Office apps on their machines
Cancel Intermedia after cutover confirmed
Move DNS (quantumwms.com + sheilaperess.com) to Cloudflare
Purchase Exchange Online Plan 1 for personal domain accounts
Cancel GoDaddy email hosting per account as each migrates
GoDaddy Decoupling Plan
DNS: move both domains to Cloudflare (transfer locks must be removed in GoDaddy first)
M365 licensing: swap GoDaddy-resold O365 Business Essentials → Business Premium
Intermedia: cancel after mail cutover confirmed
Open Items
RESOLVED: B/D compliance "Intermedia mandate" — IFG (Jen Curry) confirmed Intermedia HEX is being phased out and recommended the move to M365 (2026-05-27).
DONE: 2x Business Premium licensed + Office activated for John & Sheila (2026-05-27) — 6/03 lapse risk cleared.
SECURITY (new, 2026-06-01): force-reset John's password; get John + Sheila MFA-registered; enforce CA001 + CA003 (john@ under active password-spray, currently failing).
PST backups of John + Sheila mailboxes before Intermedia cutover.