Issue
A student or staff called (or we find out) about their account being compromised with fraudulent activity.
Environment
Information
Removing and preventing further access is the top priority when an account is compromised.
Removing groups in SuperVault is key for fraudulent activity on a staff account. Students don’t get any special access via groups. Disabling their account is sufficient.
Infrastructure is the only department that can kill a live session of someone being logged in.
Resolution
- Look up user in SuperVault
- Disable the account
- If Staff, Go to Group Memberships and remove...
- ActiveStaff
- Staff
- 2FA Exception
- Alternatively, you can remove all groups to ensure maximum security. To maintain accuracy when restoring the account, it’s important to capture a screenshot or create a list of the existing groups beforehand.
- Click Apply
- Go to Restrictions tab
- Go to Login Restrictions sub-tab
- Click Account disabled
- Click Apply
- Log into CSProd
- Look up account under User Profiles
- Lock the Account
- Contact infrastructure to kill live session after locking down an account
- If the user hasn’t been contacted, call the user and inform them of the situation.