This article describes the process in which an employee from a FASSIT-supported unit leaves the University and no longer needs their IT access or equipment.
Note: Are you trying to use this right now and are reading this line of text? Bug James to finish this!
\uD83D\uDCD8 Instructions
Reference: Separation Checklist
Willful Separation (Employee and employer are ending employment agreement on good terms)
Cancel FAMIS/AIM Access
Disable account in AiM, close associated work orders?
Override data on hard drive
Retrieve workstation from employee, check with supervisor if this is necessary
Most can typically be retrieved then /wiki/spaces/FI/pages/659257
Remove Access from servers and shared calendars
Handled at Active Directory Level, next step
Remove from DG lists and security groups
Remove user from all active directory groups
Remove from Printer and Copiers
Check printers the user had access to for mail
Remove them from scan to options
Disable Active Directory Account/Email/Two Factor Auth
PD
Find the user’s AD account, right click disable
Email will be disabled via AD account being disabled
Two Factor
Microsoft Auth: Disabled with AD account
Dualshield token: retrieve token then properly remove from user’s account (check with Bill on the proper way, we’ve been deleting tokens from the system!)
AD
Account will be disabled by IS at end of employment
Email can be kept?
Two-factor managed by IS
Email supervisor re: equipment disposition
Reach out to the user’s supervisor and ask if the machine is needed for anything critical
If not needed
Re-image the machine?
If needed, data can be recovered
Remove building and campus access
Symmetry: Remove the user from all groups
Can take a snip of current groups if needed
Lenel: User will be removed from lenel groups via being removed from Symmetry
Sync takes ~5 minutes
Remove prox and alarm access
Do you know what alarm panels they have access to? Reach out to their supervisor for more info if needed
Need actual steps/process
Remove WebLEDS Access
Access is handled via AD login, disabled PD AD account disables this access
Remove TLO Access
Remove CAD/RMS Access
When we swap back to ONESolution
Remove Keywatcher Access
UO: Handled by WorkControl
UOPD: Remove access granted from this documentation until actual steps are added (select all and remove, or disable user? Do we need this data?
Remove Milestone Access
This steps is redundant, as access is granted via AD Security Groups and was handled above
Remove AMAG Access
This steps is redundant, as access is granted via AD Security Groups and was handled above
CJIS Separation
These are given to Bill?
Remove OSP Sex Offender Access
I have never done this.
FASS IT receives separation request from FASS HR
Workstation
Retrieve workstation
Compare to PDQ to ensure we have the right machine
Do we want to copy currently installed applications due to lack of RBAC?
Keep laptop for X weeks (or wipe immediately unless otherwise told? Have it be policy, signed off, etc)
Email
Setup automatic response/forward if necessary
help user setup
PowerShell command
Permissions
AD Permissions
Copy all permissions to ticket (until RBAC policy in effect)
Include awesome PowerShell script or link to script here
Remove AD permissions from AD (and PD if necessary)
Lock account if PD user, move to un
Non-AD Permissions
AiM
Pedro?
Manitou
Card Access
Log into Symmetry, find user’s card and remove access
Set Card to disable
Dismissal
FASS IT member in charge of permissions will be given window in which user will be separated from the University
Coordinate with anyone on need-to-know basis (IS Account Admins, etc)
Reach out to IS account admins to remove UO AD access (at appropriate time)
Coordinate with supervisor for computer retrieval
Verify machine is working
Verify all accessories are included
Verify if machine can be wiped or not
See IS/General Council/ISO form about data retrieval
Coordinate removal of AD permissions with IS
Remove AD permissions, have IS account admins lock the account and remove permissions
One-off Permissions
AiM
Tableau
Manitou
Email/Exchange
Setup automatic response/forward using powershell script
Verbiage from supervisor
Remove from any DG’s or mailboxes that have been manually added without a security group
Card Access
Log into symmetry, remove card access, disable card
Inform supervisor of above status
Highlight important information in a panel like this one. To edit this panel's color or style, select one of the options in the menu.