Student/Staff Account Lockdown

Issue

A student or staff member reported (or it was discovered) that their account has been compromised with fraudulent activity.

Environment

  • Supervault
  • CSProd

Information

Removing and preventing further access is the top priority when an account is compromised.

Removing groups in SuperVault is key for fraudulent activity on a staff account. Students do not receive special access via groups; therefore, disabling their account is sufficient.

Infrastructure is the only department that can terminate a live active session.

Resolution

  1. Look up the user in SuperVault.
  2. Disable the account.
  3. If the user is Staff, go to Group Memberships and remove:
    • ActiveStaff
    • Staff
    • 2FA Exception
    • Alternatively, remove all groups to ensure maximum security. To maintain accuracy when restoring the account, capture a screenshot or create a list of the existing groups beforehand.
  4. Click Apply.
  5. Go to the Restrictions tab.
  6. Go to the Login Restrictions sub-tab.
  7. Select Account disabled.
  8. Click Apply.
  9. Log into CSProd.
  10. Look up the account under User Profiles.
  11. Lock the account.
  12. Contact Infrastructure to terminate the live session after locking down the account.
  13. If the user has not been contacted, call the user and inform them of the situation.