Home»Time Entries Audit loading ... generated 8/7/2026 at 1:31:12 pm took 0.50 seconds version: 5436fa4 helpers: v2
Territory: BMS Dates: 7/1/26 to 7/31/26 Company: IC [x] Ticket: all User: all Type: Remote [x] Role: all Bill: all Timesheet: all 6/29 7/6 7/13 7/20 7/27 Board: all Entry Status: all Ticket Status: all Issue: Notes longer than 500 characters [x] [reset] Progress: 100% (3 of 3)
| row | id | Terr | Company | User | Date | Day | Start | End | Actual | Billed | Deduct | Inv Amt | Work Type | Work Role | Bill | Timesheet | Board | Entry Status | Ticket Status | Ticket # | Ticket Summary | Int Notes | Audit Done | Audit Notes | Notes | # issues | all issues | errors | warnings | notices |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1 | 42161 | BMS | IC | fdrewett | 7/3 | 9:30 am | 10:30 am | 1.00 | 1.00 | 0 | 125.00 | Remote | Standard Technician | Billable | 6/29 | Help Desk 2.1 | ReadyToBill | -Closed | 78900 | Fraud Email | 1 | 8/6 CS long notes ok | Security incident response - Microsoft 365 account \(Kole Spathelf\) On July 3, our monitoring partner detected that an outside party had signed into Kole Spathelf's Microsoft 365 account from an unauthorized location. The account did not have multi-factor authentication turned on, which allowed the sign-in using only the password. The account was automatically locked down within about 11 minutes of detection, cutting off the intruder's access. We then performed a full investigation and confirmed the intruder did not set up any hidden access, forwarding, or other means to get back in. During the brief access window, the intruder viewed roughly 110 emails, mostly routine company announcements and pay notifications. There was no evidence that any email was sent, moved, or deleted from the account. To secure the account, we reset the password and turned on multi-factor authentication, which will prompt Kole to set up a second verification step at next sign-in. The account has been safely returned to normal use. Recommended next step: we advise enabling multi-factor authentication across all user accounts in your Microsoft 365 environment to prevent this type of intrusion going forward. We're happy to schedule this with you. | 1 | Notices: Notes: Notes longer than 500 characters | Notes: Notes longer than 500 characters | ||||
| 2 | 42162 | BMS | IC | fdrewett | 7/3 | 10:45 am | 11:45 am | 1.00 | 1.00 | 0 | 125.00 | Remote | Standard Technician | Billable | 6/29 | Help Desk 2.1 | ReadyToBill | -Closed | 78900 | Fraud Email | 1 | 8/6 CS long notes ok | Security incident response and account decommission, Microsoft 365 account \(Dijon White\) On July 3, our monitoring partner detected that an outside party had gained access to Dijon White's Microsoft 365 account from an unauthorized location, using a stolen sign-in session. This was the second such attempt against your organization that day from the same source. The account was automatically locked down within about 6 minutes of detection, cutting off the intruder's access. We then performed a full investigation and confirmed the intruder did not set up any hidden access, forwarding, or other means to get back in. Because this account belonged to an employee whose last day was July 2, and at your direction, we converted the mailbox to an archive-only mailbox \(retaining the email for your records\), blocked all sign-in to the account, and removed its paid license to free up the subscription seat. Recommended next step: we advise enabling multi-factor authentication across all user accounts and reviewing sign-in protections for your Microsoft 365 environment, as your organization was targeted twice in one day. We're happy to schedule this with you. | 1 | Notices: Notes: Notes longer than 500 characters | Notes: Notes longer than 500 characters | ||||
| 3 | 42354 | BMS | IC | rclingan | 7/6 | 8:00 pm | 10:00 pm | 2.00 | 2.00 | 0 | 250.00 | Remote | Standard Technician | Billable | 7/6 | Help Desk 2.1 | Open | -Closed | 78900 | Fraud Email | 1 | 8/6 CS long notes ok | TICKET NOTES — M365 Licensing Audit & Identity Security Scoping WORK PERFORMED: - Exported tenant license assignments via Graph PowerShell \(Get-MgSubscribedSku / Get-MgUser\); built SKU GUID-to-name map - Analyzed 179 accounts: 82 unlicensed \(shared mailboxes/service accts\), 68 Business Basic, 24 Business Standard, 3 Office 365 E3 - FINDING: Zero Entra ID P1 in tenant. Conditional Access not possible on current licensing. Note: O365\_BUSINESS\_PREMIUM SKU = Business Standard \(legacy naming\), not Business Premium - Exported per-user mailbox sizes via ExchangeOnlineManagement \(Get-EXOMailboxStatistics\). Resolved module install + WAM broker auth failure \(-DisableWAM\) - Cross-referenced mailbox sizes against license tiers to build three-tier licensing recommendation ENVIRONMENT NOTES: - On-prem AD \(no Entra Connect sync currently\), ESXi host w/ Sage server + DC, NAS, 2 sites w/ S2S VPN - ~24 desktop users on AD accounts; ~12 field laptops on LOCAL accounts \(unmanaged\) - NinjaRMM on all PCs incl. field laptops; Huntress EDR + ITDR \(retain\); Inky Phish Fence \(displace w/ Defender for O365 P1 — client wants off Inky post-Kaseya acquisition\) RECOMMENDATION SUMMARY: - Phase 1 \(38 hrs\): AD prep/IdFix/UPN alignment, Entra Connect w/ PHS + hybrid join, Intune auto-enroll GPO, CA policy set \(report-only -> enforce\), MFA/passkey rollout - Phase 2 \(20 hrs\): Field laptop migration remote via Ninja — Autopilot hash collection, ProfWiz local-to-Entra profile migration, no device collection needed - Phase 3 \(50 hrs, modular\): Intune foundation, Autopilot, app deployment, Defender for Business as AV layer under Huntress, Defender for O365 P1 + Inky cutover, MAM - Licensing: 38x Business Premium \(24 Standard upgrades, 3 E3 swaps, 11 Basic w/ mailboxes >F3 2GB limit\), 57x F3 + DfO add-on \(phone-profile field users\). Est. delta ~+$632/mo, partially offset by Inky cancellation - Pending: laptop-to-user mapping from Ninja inventory — any F3-slated user w/ company laptop moves to Premium DELIVERABLES: - One-page proposal doc \(scope/hours/licensing\) - Per-user license recommendation CSV \(95 users w/ rationale\) NEXT STEPS: - Pull device-to-user assignments from NinjaRMM - Client decision on Huntress Managed SAT \(no conflict w/ BP licensing — attack sim requires DfO P2, not included\) | 1 | Notices: Notes: Notes longer than 500 characters | Notes: Notes longer than 500 characters |
Legend:
(hover over fields for details)
Tickets with over 5 hours in the current view (1)
| Hours | Ticket # | Company | Ticket Summary |
|---|---|---|---|
| 7.75 | 78900 | IC | Fraud Email |
Notices
| Field | Message | Count |
|---|---|---|
| Notes | Notes longer than 500 characters | 3 |
| Total | 3 | |