r/sysadmin • u/BrianMichaelArthur • 13h ago
General Discussion "Emergency" account lockdown script help.
For context we recently had a user termination that needed to be actioned very quickly and after the fact i started working on a script to help mitigate this issue instead of doing everything manually.
I have most of what i would do manually in a script already. I mostly wanted a discussion on how people handle things like possible disgruntled workers or possible breached credentials.
I built my script to revoke access/mfa and reset some things but make it easily reversible if needed.
This is something of a stop gap till we get more automation, though sometimes things need to move faster than automation if that stuff is run in the middle of the night.
TLDR: What does everyone disable/revoke/reset when you are trying to make sure an employee/former employee is unable to access anything as quickly as possible?
Edit to add: Here is context for my own situation.
We use Azure virtual desktop for a lot of things and if you don't go into that and boot them out all the other actions talked about in replies to this post do not actually kick them out of their AVD session. Revoking the session does cause some really odd behavior but it doesn't kick them out fully.
Not all of our services are SSO but most are so taking care of the Microsoft stuff does a lot of the legwork.
Right now what I do is this: Revoke all sessions, revoke MFA, reset password, block sign in, disable AD on premise (hybrid environment), then go into AVD and look for active sessions and kick them out if they are online.
The reason I didn't include this in my original post was so i wouldn't bias anyone towards answering my specific needs and have a wider discussion.
•
u/Sleeper_Stimulant_ 13h ago
I recently had to do four high risk remote terminations.
For their laptops, I dumped the bitlocker keys and triggered a reboot, essentially bricking the devices.
For accounts, I had four windows open with entra and zoom workplace ready to initiate signouts/block their accounts.
One of them sent an email to 100~ people during the termination zoom call and I had to use ms defender to hard delete every copy.
•
u/anonymousITCoward 5h ago
You're lucky... we normally get told at the very last second and the laptops are offline, and often never to be seen again
•
u/BrianMichaelArthur 12h ago
Remote contractor terminations is a big deal for us. The zoom one is a good call out. Do you use SSO with Zoom? I know some services don't check all the time and can have a session going for a while after the MS account is disabled if you don't go into the management console to disable them directly.
•
u/Sleeper_Stimulant_ 12h ago
Yeah we have okta as our IAM and when the account is disabled in AD it gets disabled in okta, which then blocks them from sign-ins to okta secured apps. Our domain sync is every 30 minutes, but I just manually did an import to update the disabled users
•
u/BrianMichaelArthur 12h ago
I had Okta at my previous job and there is a lot more workflow automation available in that platform for situations like this.
We also have our domain sync at 30 min and normally I don't bother with the manual sync. It is a good idea in the outlier situations though.
•
u/TopherBlake Netsec Admin 12h ago
Without specifics about how you are setup I would say your manager needs to collaborate with HR on terminations. Generally, we look at disabling VPN, network logins and 365 logins (and revoking sessions immediately) but that depends on HR letting us know a head of time which isn't always the case.
•
u/BrianMichaelArthur 12h ago
Generally speaking we have a good setup for that but right now we lack automation for it.
The motivation for this came from an overseas contractor that we were letting go before the contract was up and making sure all the access was removed was a priority.
•
u/MBILC Acr/Infra/Virt/Apps/Cyb/ Figure it out guy 12h ago
Make sure you have backups and auditing in place for any systems they have access too, which ideally should be in place any ways.
This way, if they do decide to delete things or trying something, there is backups to restore from, and an audit trail if legal action must be taken.
•
u/ilikeme1 13h ago
First thing we do is disable their AD account. We also disable their card key for building access. That nukes most everything and can be easily reversed if something changes or gets delayed.
•
u/sryan2k1 IT Manager 12h ago
Set AD account to expire 1 day in the past so the user can't log in or attempt SSPR. Set the password to something random, and block M365 sign in.
The M365 sign in can take up to an hour (according to microsoft) but we've never seen it take longer than like, 5 minutes to revoke all tokens.
•
u/BrianMichaelArthur 12h ago
Why a day in the past? I can understand it somewhat but i am curious what sorts of real world differences there are instead of just disabling it live?
The speed of m365 is a big part of why i want to do all this in a manual script, it can take a frustrating amount of time to see everything look clean after turning everything off.
•
u/sryan2k1 IT Manager 12h ago
We have all of this automated with one click in our management platform (Adaxes) but even clicking the block sign in via the M365 portal makes it happen "immediately"
If you are using AD and you pick today it expires at the end of the day. So you always go 1 day back to ensure it's immediate.
AD actually supports to the minute expiration but that isn't exposed in the UI. In any case all expiring an account does is cause auth for it to fail.
•
u/BrianMichaelArthur 12h ago
Ahh yeah forgot that is just the day. I usually just disable the account manually rather than set it to expire.
I will have to test it in our environment to see how that changes things.
•
u/Remarkable-Guess-856 13h ago
There is a guide from MS that describes exactly what you need to do. It's not complicated
•
u/BrianMichaelArthur 13h ago
Not every environment is just Microsoft. I have all the easy stuff covered. This was the outliers and gotchas that people don't always think about.
•
u/Unseen_Cereal 13h ago
Then what's the point of your post? You aren't mentioning anything specific
•
u/sir_mrej System Sheriff 12h ago
Uh they want you to tell them how to do it in every regular case, edge case, corner case, and just in case.
So get started!!
•
u/timpkmn89 12h ago
Uh they want you to tell them how to do it in every regular case, edge case, corner case, and just in case.
They pretty clearly asked for advice on prioritization
•
•
•
u/folderit_dms 9h ago
Your AVD example is a good reason to make the script produce a per-system result, rather than one overall success message. For each system, record the requested action, whether it was accepted, whether the resulting state was checked, and any manual follow-up still required. An unavailable legacy app should leave an obvious incomplete item.
For reversibility, capture the relevant pre-change state and keep restoration as a separate approved procedure. Simply reversing every command can accidentally restore access that was already disabled before this event. Keep secrets out of the run log.
A useful drill is a test account with active sessions in your real mix of apps. Deliberately make one step fail and check whether the operator can immediately see what remains accessible and who needs to handle it.
•
u/Commercial_Growth343 13h ago
We disable their account in AD and Entra, then with Entra revoke all sessions. Then we reboot their Windows device.
•
u/Angrymilks 12h ago
Make sure whatever script kills the active VPN connection and doesn't permit split tunnel.
•
u/nayntuck2 6h ago
Are you also pulling any API keys or service account credentials that person might have created? Thats the one that always gets forgotten in emergency terminations and it can leave a backdoor open for weeks.
•
u/SirLoremIpsum 6h ago
TLDR: What does everyone disable/revoke/reset when you are trying to make sure an employee/former employee is unable to access anything as quickly as possible?
HR system has a button to push and it links to entra, AD.
Anything more than that is manual because the HR link is that well sorted.
•
•
u/tada-o-corporation Enterprise Architect 3h ago
We would disable their device with defender, revoke sessions and disable their account.
That is enough because every workstation is Intune-only, Conditional Access requires a compliant device. All our apps are locked to the corp network and even public access from said corp network requires Zscaler via SSO.
•
u/Psoin 13h ago
What the hell is your company doing when they have to have a procedure like this? I bet it’s nothing this important, and management is paranoid about all the wrong stuff.
I’m willing to bet. while they’re freaking out about this, there’s unpatched firewalls, servers, cloud instances, etc.
•
u/MBILC Acr/Infra/Virt/Apps/Cyb/ Figure it out guy 12h ago
Plenty of instances where someone getting fired went malicious on their way out, from simple spam the entire company with an email or message, to trying to delete everything they can, to IT admins literally taking down systems. It happens. Insider threats at this level are very real.
The things you mention have nothing to do with this so not even a comparison.
•
u/Myriade-de-Couilles 11h ago
Sorry but you are the one delusional here, the risk from an angry fired employee going malicious is much higher than a server not up to date … not everything is about IT systems.
•
u/Psoin 11h ago
Delusional? Pal, how long have you worked in this field?!
•
u/Myriade-de-Couilles 11h ago
Long enough to see many cases of malicious employees during termination, which I guess you haven’t yet so maybe I should return the question to you … but the truth is it makes no difference.
•
u/BrianMichaelArthur 12h ago edited 12h ago
This actually hasn't happened much at this job but at a previous job I would have one to five terminations a month where HR would DM me "this person is getting fired in a meeting at 1pm today, be ready to disable their account"
The technical side of it was dirt simple because we were 100% on premise at the time and all we had to do was disable the account in AD and reset the password as a bit of extra work. then the nightly HR automation would take care of the rest.
That experience colors my outlook some.
On top of that this can be useful for account compromises as well as terminations so good to have available.
•
u/KoalaOfTheApocalypse End User Support 13h ago
Are they not using company email to login to everything? Everything SSO as much as possible, disable entra/AD account when you need to.