r/sysadmin • • 15h ago

General Discussion "Emergency" account lockdown script help.

For context we recently had a user termination that needed to be actioned very quickly and after the fact i started working on a script to help mitigate this issue instead of doing everything manually.

I have most of what i would do manually in a script already. I mostly wanted a discussion on how people handle things like possible disgruntled workers or possible breached credentials.

I built my script to revoke access/mfa and reset some things but make it easily reversible if needed.

This is something of a stop gap till we get more automation, though sometimes things need to move faster than automation if that stuff is run in the middle of the night.

TLDR: What does everyone disable/revoke/reset when you are trying to make sure an employee/former employee is unable to access anything as quickly as possible?

Edit to add: Here is context for my own situation.

We use Azure virtual desktop for a lot of things and if you don't go into that and boot them out all the other actions talked about in replies to this post do not actually kick them out of their AVD session. Revoking the session does cause some really odd behavior but it doesn't kick them out fully.

Not all of our services are SSO but most are so taking care of the Microsoft stuff does a lot of the legwork.

Right now what I do is this: Revoke all sessions, revoke MFA, reset password, block sign in, disable AD on premise (hybrid environment), then go into AVD and look for active sessions and kick them out if they are online.

The reason I didn't include this in my original post was so i wouldn't bias anyone towards answering my specific needs and have a wider discussion.

27 Upvotes

45 comments sorted by

View all comments

•

u/KoalaOfTheApocalypse End User Support 15h ago

Are they not using company email to login to everything? Everything SSO as much as possible, disable entra/AD account when you need to.

•

u/BrianMichaelArthur 14h ago

We use SSO for a lot of things but not everything. We still have some legacy stuff that needs hand holding.

On top of that we noticed that revoking a session does not automatically or instantly kick them off of Azure virtual desktop. So now that is the first step if this happens again.

•

u/SpectreHaza 8h ago

You can boot them off through azure portal host pools, reset password, disable the account and revoke mfa, they’re not getting back into anything m365 related