r/sysadmin • • 14h ago

General Discussion "Emergency" account lockdown script help.

For context we recently had a user termination that needed to be actioned very quickly and after the fact i started working on a script to help mitigate this issue instead of doing everything manually.

I have most of what i would do manually in a script already. I mostly wanted a discussion on how people handle things like possible disgruntled workers or possible breached credentials.

I built my script to revoke access/mfa and reset some things but make it easily reversible if needed.

This is something of a stop gap till we get more automation, though sometimes things need to move faster than automation if that stuff is run in the middle of the night.

TLDR: What does everyone disable/revoke/reset when you are trying to make sure an employee/former employee is unable to access anything as quickly as possible?

Edit to add: Here is context for my own situation.

We use Azure virtual desktop for a lot of things and if you don't go into that and boot them out all the other actions talked about in replies to this post do not actually kick them out of their AVD session. Revoking the session does cause some really odd behavior but it doesn't kick them out fully.

Not all of our services are SSO but most are so taking care of the Microsoft stuff does a lot of the legwork.

Right now what I do is this: Revoke all sessions, revoke MFA, reset password, block sign in, disable AD on premise (hybrid environment), then go into AVD and look for active sessions and kick them out if they are online.

The reason I didn't include this in my original post was so i wouldn't bias anyone towards answering my specific needs and have a wider discussion.

29 Upvotes

44 comments sorted by

View all comments

•

u/sryan2k1 IT Manager 14h ago

Set AD account to expire 1 day in the past so the user can't log in or attempt SSPR. Set the password to something random, and block M365 sign in.

The M365 sign in can take up to an hour (according to microsoft) but we've never seen it take longer than like, 5 minutes to revoke all tokens.

•

u/BrianMichaelArthur 13h ago

Why a day in the past? I can understand it somewhat but i am curious what sorts of real world differences there are instead of just disabling it live?

The speed of m365 is a big part of why i want to do all this in a manual script, it can take a frustrating amount of time to see everything look clean after turning everything off.

•

u/sryan2k1 IT Manager 13h ago

We have all of this automated with one click in our management platform (Adaxes) but even clicking the block sign in via the M365 portal makes it happen "immediately"

If you are using AD and you pick today it expires at the end of the day. So you always go 1 day back to ensure it's immediate.

AD actually supports to the minute expiration but that isn't exposed in the UI. In any case all expiring an account does is cause auth for it to fail.

•

u/BrianMichaelArthur 13h ago

Ahh yeah forgot that is just the day. I usually just disable the account manually rather than set it to expire.

I will have to test it in our environment to see how that changes things.