TechMonkey Posted November 17, 2020 Posted November 17, 2020 We have auditors in and they want proof we locked the accounts of those on furlough. We never had account locked as an audited item. Just wondering if the hive mind can think of a way to prove the accounts were locked. I don't think it is possible but I want to be able to say definitely. Many thanks
Vegas Posted November 17, 2020 Posted November 17, 2020 net user "username" /domain This should give you enough info to satisfy them. 1
Ditto Posted November 17, 2020 Posted November 17, 2020 There are a few free tools out there, but here is one article that may help https://community.spiceworks.com/how_to/166859-view-ad-logs-in-event-viewer. It takes you through the steps of enabling Active Directory before hand - hopefully you already have that on. Out if interest, who is doing the audit? Is it internal, DfE or other gov body, or someone else. Even if the accounts remained open, I don't think that is proof furloughed staff were working and if a member of staff broke the working guidance, I'd say that's different to being followed then asked to work, which would of course land someone on hot water. 1
mavhc Posted November 17, 2020 Posted November 17, 2020 If you can't tell if they did any work, isn't their job pointless? Seems an arbitrary question whether their account was locked, what would that imply? Cached login on offline laptop would still work 1
TechMonkey Posted November 17, 2020 Author Posted November 17, 2020 @Vegas, thanks but the accounts are now open, they want a retrospective view. @Ditto, Unfortunately not. Never thought I'd need to know if an account was locked in the past! It is our Financial Audit, I guess they are trying to ensure we won't be hit by HMRC for not having proof. @mavhc, we want to show they didn't do any work (don't get me started on trying to prove a negative). Just because they were told not work doesn't mean their job is pointless, just that at that point in time they were not essential. None of the staff have work issued laptops and if their account is locked they would not be able to access any school resources. If they decided to do some work themselves that is on them, but the school was not facilitating them. 1
KASIT97 Posted November 17, 2020 Posted November 17, 2020 Agree with mavhc, just because their domain account was locked it doesn't stop them logging in on a cached device. Wonder what the reasoning behind it is? EDIT: just seen your recent post, disregard
psydii Posted November 17, 2020 Posted November 17, 2020 https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4725 You might have to restore the event logs from a backup. 1
TechMonkey Posted November 17, 2020 Author Posted November 17, 2020 https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4725 You might have to restore the event logs from a backup. Thanks psydii, but that needs to be set up beforehand.
Rob_D Posted November 17, 2020 Posted November 17, 2020 Is this documented somewhere a change log, a support site request? If we do something like this, we tent to drop a note in the description field as to why it was locked and when. Would that be enough? 1
Ditto Posted November 17, 2020 Posted November 17, 2020 This has now become an even more interesting question! Given the amount of tracking current OS's perform, it'll be surprising there isn't some record somewhere, but if it really does rely on 'auditing' to be turned on, then I guess it's going to need to be a more creative 'proof'. Did you get the request to disable the accounts via email or other system? Did you notify that they were disabled and can you audit that? My Windows AD, and the like, experience is a fraction of many on here. If it were G Suite, I would be able to audit any file access between dates for given users easily. Putting 'proof' to one side, it might be the best that can be provided to assure the finance auditors. I'm now interest to see the outcome of this challenge - do let us know how it pans out.
mavhc Posted November 17, 2020 Posted November 17, 2020 M365 and GSuite have logs of when people logged in
TechMonkey Posted November 17, 2020 Author Posted November 17, 2020 Thanks Rob, I think this may be the tack I have to take. Print some emails out and hope that is satisfactory. Nice to be told about this 9 months later when most records are only 90 days!
TechMonkey Posted November 17, 2020 Author Posted November 17, 2020 @Ditto and @mavhc - Funnily enough this is the route I started taking as we sync with AzureAD. But as far as I can tell records are only kept for 90 days. I'll keep digging.
mavhc Posted November 17, 2020 Posted November 17, 2020 I'd just go with: they didn't send any emails
Andrew_C Posted November 17, 2020 Posted November 17, 2020 First question - did you lock the accounts? Mine wasn't while I was furloughed as it was the route to being told when I was and wasn't "off".
TechMonkey Posted November 17, 2020 Author Posted November 17, 2020 I did. Funnily enough it caused me great mirth when I locked the accounts, on direct instruction, they sent out emails to all staff to tell them what was happening and couldn't understand why staff couldn't read it 1
jmak Posted November 17, 2020 Posted November 17, 2020 I did. Funnily enough it caused me great mirth when I locked the accounts, on direct instruction, they sent out emails to all staff to tell them what was happening and couldn't understand why staff couldn't read it I think you've got your solution; tell them that story and they will know it really happened from the look on your face! 1
2097 Posted December 9, 2020 Posted December 9, 2020 Do you mean you "disabled" the accounts ? If so, Exchange/outlook still works internally with a disabled account . As their credentials are cached and still authenticated. We have had this issue and now have to delete/disable the exchange accounts also.
TechMonkey Posted December 9, 2020 Author Posted December 9, 2020 Do you mean you "disabled" the accounts ? If so, Exchange/outlook still works internally with a disabled account . As their credentials are cached and still authenticated. We have had this issue and now have to delete/disable the exchange accounts also. Luckily it was for furlough so they weren't on site or internal. You can force accounts to re-auth for internal or laptops working off site.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now