Home»Time Entries Audit loading ... generated 8/7/2026 at 12:34:26 pm took 1.08 seconds version: 5436fa4 helpers: v2

Territory: BMS Dates: 7/1/26 to 7/31/26 Company: IC [x] Ticket: 78900 [x] User: all Type: all Role: all Bill: all Timesheet: all  6/29 7/6 7/13 7/20 7/27 Board: all Entry Status: all Ticket Status: all Issue: all [reset] Progress: 100% (4 of 4)

row id Terr Company User Date Day Start End Actual Billed Deduct Inv Amt Work Type Work Role Bill Timesheet Board Entry Status Ticket Status Ticket # Ticket Summary Int Notes Audit Done Audit Notes Notes # issues all issues errors warnings notices
1 42161 BMS IC fdrewett 7/3 9:30 am 10:30 am 1.00 1.00 0 125.00 Remote Standard Technician Billable 6/29 Help Desk 2.1 ReadyToBill -Closed 78900 Fraud Email 1 8/6 CS long notes ok Security incident response - Microsoft 365 account \(Kole Spathelf\) On July 3, our monitoring partner detected that an outside party had signed into Kole Spathelf's Microsoft 365 account from an unauthorized location. The account did not have multi-factor authentication turned on, which allowed the sign-in using only the password. The account was automatically locked down within about 11 minutes of detection, cutting off the intruder's access. We then performed a full investigation and confirmed the intruder did not set up any hidden access, forwarding, or other means to get back in. During the brief access window, the intruder viewed roughly 110 emails, mostly routine company announcements and pay notifications. There was no evidence that any email was sent, moved, or deleted from the account. To secure the account, we reset the password and turned on multi-factor authentication, which will prompt Kole to set up a second verification step at next sign-in. The account has been safely returned to normal use. Recommended next step: we advise enabling multi-factor authentication across all user accounts in your Microsoft 365 environment to prevent this type of intrusion going forward. We're happy to schedule this with you. 1 Notices: Notes: Notes longer than 500 characters Notes: Notes longer than 500 characters
2 42162 BMS IC fdrewett 7/3 10:45 am 11:45 am 1.00 1.00 0 125.00 Remote Standard Technician Billable 6/29 Help Desk 2.1 ReadyToBill -Closed 78900 Fraud Email 1 8/6 CS long notes ok Security incident response and account decommission, Microsoft 365 account \(Dijon White\) On July 3, our monitoring partner detected that an outside party had gained access to Dijon White's Microsoft 365 account from an unauthorized location, using a stolen sign-in session. This was the second such attempt against your organization that day from the same source. The account was automatically locked down within about 6 minutes of detection, cutting off the intruder's access. We then performed a full investigation and confirmed the intruder did not set up any hidden access, forwarding, or other means to get back in. Because this account belonged to an employee whose last day was July 2, and at your direction, we converted the mailbox to an archive-only mailbox \(retaining the email for your records\), blocked all sign-in to the account, and removed its paid license to free up the subscription seat. Recommended next step: we advise enabling multi-factor authentication across all user accounts and reviewing sign-in protections for your Microsoft 365 environment, as your organization was targeted twice in one day. We're happy to schedule this with you. 1 Notices: Notes: Notes longer than 500 characters Notes: Notes longer than 500 characters
3 42151 BMS IC ggonzales 7/2 10:38 am 1:53 pm 3.25 3.25 0 406.25 Remote Standard Technician Billable 6/29 Help Desk 2.1 ReadyToBill -Closed 78900 Fraud Email 0 Steps taken: * Investigating incedent * Found and adjusted various accounts noted internally * Called clients and assisted with getting them back into after confirming everything was clean Next Steps: * Continue assisting with cleanup 0
4 42377 BMS IC rclingan 7/2 11:25 am 11:30 am 0.08 1.00 0 25.00 Travel Standard Technician Billable 6/29 Help Desk 2.1 ReadyToBill -Closed 78900 Fraud Email 0 travel for onsite visit to deal with initial security incidents 0
5 42378 BMS IC rclingan 7/2 11:30 am 11:48 am 0.30 1.00 0 125.00 Onsite Standard Technician Billable 6/29 Help Desk 2.1 ReadyToBill -Closed 78900 Fraud Email 0 remediated accounts with courtney and provided updated information to be given to users. 0
6 42358 BMS IC rclingan 7/6 7:30 pm 8:00 pm 0.50 0.50 0 62.50 Remote Standard Technician Billable 7/6 Help Desk 2.1 Open -Closed 78900 Fraud Email 0 remediation on another email breach. same datacenter ip addresses for logins, user breached had MFA enabled Token/aitm attack pattern consistent across breached accounts. we will need to setup conditional access policies to prevent these attacks. 0
7 42354 BMS IC rclingan 7/6 8:00 pm 10:00 pm 2.00 2.00 0 250.00 Remote Standard Technician Billable 7/6 Help Desk 2.1 Open -Closed 78900 Fraud Email 1 8/6 CS long notes ok TICKET NOTES — M365 Licensing Audit & Identity Security Scoping WORK PERFORMED: - Exported tenant license assignments via Graph PowerShell \(Get-MgSubscribedSku / Get-MgUser\); built SKU GUID-to-name map - Analyzed 179 accounts: 82 unlicensed \(shared mailboxes/service accts\), 68 Business Basic, 24 Business Standard, 3 Office 365 E3 - FINDING: Zero Entra ID P1 in tenant. Conditional Access not possible on current licensing. Note: O365\_BUSINESS\_PREMIUM SKU = Business Standard \(legacy naming\), not Business Premium - Exported per-user mailbox sizes via ExchangeOnlineManagement \(Get-EXOMailboxStatistics\). Resolved module install + WAM broker auth failure \(-DisableWAM\) - Cross-referenced mailbox sizes against license tiers to build three-tier licensing recommendation ENVIRONMENT NOTES: - On-prem AD \(no Entra Connect sync currently\), ESXi host w/ Sage server + DC, NAS, 2 sites w/ S2S VPN - ~24 desktop users on AD accounts; ~12 field laptops on LOCAL accounts \(unmanaged\) - NinjaRMM on all PCs incl. field laptops; Huntress EDR + ITDR \(retain\); Inky Phish Fence \(displace w/ Defender for O365 P1 — client wants off Inky post-Kaseya acquisition\) RECOMMENDATION SUMMARY: - Phase 1 \(38 hrs\): AD prep/IdFix/UPN alignment, Entra Connect w/ PHS + hybrid join, Intune auto-enroll GPO, CA policy set \(report-only -> enforce\), MFA/passkey rollout - Phase 2 \(20 hrs\): Field laptop migration remote via Ninja — Autopilot hash collection, ProfWiz local-to-Entra profile migration, no device collection needed - Phase 3 \(50 hrs, modular\): Intune foundation, Autopilot, app deployment, Defender for Business as AV layer under Huntress, Defender for O365 P1 + Inky cutover, MAM - Licensing: 38x Business Premium \(24 Standard upgrades, 3 E3 swaps, 11 Basic w/ mailboxes >F3 2GB limit\), 57x F3 + DfO add-on \(phone-profile field users\). Est. delta ~+$632/mo, partially offset by Inky cancellation - Pending: laptop-to-user mapping from Ninja inventory — any F3-slated user w/ company laptop moves to Premium DELIVERABLES: - One-page proposal doc \(scope/hours/licensing\) - Per-user license recommendation CSV \(95 users w/ rationale\) NEXT STEPS: - Pull device-to-user assignments from NinjaRMM - Client decision on Huntress Managed SAT \(no conflict w/ BP licensing — attack sim requires DfO P2, not included\) 1 Notices: Notes: Notes longer than 500 characters Notes: Notes longer than 500 characters
8 42356 BMS IC rclingan 7/7 10:28 am 10:45 am 0.28 1.00 0 25.00 Travel Standard Technician Billable 7/6 Help Desk 2.1 Open -Closed 78900 Fraud Email 1 8/6 CS fixed travel entered as remote travel for onsite visit 0
9 42355 BMS IC rclingan 7/7 10:45 am 11:06 am 0.35 1.00 0 125.00 Onsite Standard Technician Billable 7/6 Help Desk 2.1 Open -Closed 78900 Fraud Email 0 Onsite visit to discuss Identity and licensing upgrade to prevent continued email breaches and reduce the amount of remediations needed. 0

Legend:
(hover over fields for details)

Error (0)
Warning (0)
Notice (3)


Tickets with over 5 hours in the current view (1)

Hours Ticket # Company Ticket Summary
9.75 78900 IC Fraud Email


Notices

Field Message Count
Notes  Notes longer than 500 characters  3
Total  3


42161 - fdrewett - 7/3 9:30 am - 78900 - Fraud Email
Notes longer than 500 characters

42162 - fdrewett - 7/3 10:45 am - 78900 - Fraud Email
Notes longer than 500 characters

42354 - rclingan - 7/6 8:00 pm - 78900 - Fraud Email
Notes longer than 500 characters