0% found this document useful (0 votes)
3 views5 pages

System Administrator - Remote Test Assignment

The document outlines a comprehensive guide for a System Administrator's remote test assignment, covering Microsoft 365 user onboarding, incident handling, network security using Sophos Firewall, backup and recovery strategies, and IT onboarding processes for new remote employees. Key practices include enabling Multi-Factor Authentication (MFA), assigning licenses, and ensuring strong security measures while maintaining operational efficiency. It also highlights the top IT risks in remote teams and emphasizes the importance of security over speed in backup processes.

Uploaded by

team.fasade
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
3 views5 pages

System Administrator - Remote Test Assignment

The document outlines a comprehensive guide for a System Administrator's remote test assignment, covering Microsoft 365 user onboarding, incident handling, network security using Sophos Firewall, backup and recovery strategies, and IT onboarding processes for new remote employees. Key practices include enabling Multi-Factor Authentication (MFA), assigning licenses, and ensuring strong security measures while maintaining operational efficiency. It also highlights the top IT risks in remote teams and emphasizes the importance of security over speed in backup processes.

Uploaded by

team.fasade
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

System Administrator – Remote Test Assignment

PART 1 – Microsoft 365 User Onboarding


1. Create a User in Microsoft 365

1. Log in to the Microsoft 365 Admin Center.


2. Go to Users → Active users → Add users.
3. Enter the user’s name and username (email address).
4. Set a temporary password.
5. Enable Change password at first sign-in.
6. Save the user account.

2. Assign Licenses

1. Open the user account.


2. Assign the correct Microsoft 365 license.
3. Make sure these services are enabled:
○ Outlook (Email)
○ Microsoft Teams
○ OneDrive
4. Confirm the license is active.

3. Multi-Factor Authentication (MFA)

MFA (Multi-Factor Authentication) adds an extra security step during login.

Steps:

1. Go to Azure AD / Entra ID → Users.


2. Enable MFA for the user.
3. Require at least two authentication methods:
○ Microsoft Authenticator app (primary)
○ Phone number (backup)
4. Instruct the user to complete MFA registration at first login.
5. Block legacy authentication methods if possible.

Why MFA is important:

● Protects accounts even if passwords are stolen.


● Reduces risk of phishing and account takeover.
● Very important for remote work environments.

4. Access Setup (Email, Teams, OneDrive)

● Email mailboxes are created automatically.


● Team access works after license assignment.
● OneDrive is created at first login.
● Add the user to required Teams or groups.

5. Basic Security Best Practices

● Use strong passwords and MFA.


● Give only required access.
● Do not assign admin rights unless needed.
● Record the setup in IT documentation.

PART 2 – Remote Incident Handling & Prioritization


Incident Priority (Based on Business Impact)
1. 3 users cannot access email – Highest priority.
2. Laptop not booting after Windows update – High priority.
3. Unstable VPN connection – Medium priority.

What I Check First

● Email issue:
○ Check Microsoft 365 service status.
○ Check login, password, or MFA issues.
● Laptop issue:
○ Ask for an error message.
○ Check if recovery mode is available.
● VPN issue:
○ Check internet connection.
○ Review VPN login and settings.

Issues I Handle Myself

● Email access problems (password, MFA registration issues).


● Password resets and MFA re-registration.
● Basic VPN troubleshooting, including MFA prompts.
● Initial Windows update checks.
When to Escalate

● Hardware failure.
● Windows reinstall needed.
● Firewall or ISP issue beyond my access.

PART 3 – Remote Network & Firewall Thinking (Sophos Firewall)


General Approach
The goal is to maintain strong security while ensuring employees can work efficiently. Security controls
should reduce risk without disrupting daily operations.
Use Sophos Firewall to protect the network while allowing employees to work normally. Security should
not interrupt daily tasks. MFA is enforced for remote access and VPN connections to reduce the risk of
unauthorized access.

Security Measures Using Sophos Firewall

1. Firewall Rules
○ Allow only required ports and services.
○ Block unnecessary inbound traffic from the internet.
2. VPN for Remote Users (With MFA)
○ Use Sophos SSL VPN or IPsec VPN for remote access.
○ Require user authentication with username and password.
○ Enforce Multi-Factor Authentication (MFA) for VPN logins.
○ MFA ensures that even if VPN credentials are stolen, access is still blocked.
3. Web Filtering
○ Block malicious and phishing websites.
○ Restrict risky website categories.
4. Intrusion Prevention System (IPS)
○ Detect and block suspicious network activity and known attacks.
5. Antivirus & Threat Protection
○ Scan network traffic for malware and ransomware.

Monitoring & Logs

● Monitor VPN connections and MFA login attempts.


● Review firewall alerts and blocked traffic.
● Investigate repeated failed VPN or MFA attempts.
PART 4 – Backup & Recovery (Remote Context)
Backup Strategy
● Daily backups for:
○ Email
○ OneDrive
○ SharePoint
● Use secure cloud backup solution.
● Define retention period.

Restore Process

1. Confirm what data was deleted.


2. Check recycle bin or version history.
3. Restore from backup if needed.
4. Confirm data with the user.

Speed vs Security

Security is more important than speed. Backups must be encrypted, access-controlled, and protected from
ransomware or unauthorized access.

PART 5 – SOP: IT Onboarding Process for New Remote Employees


Account Creation
● Create Microsoft 365 account.
● Assign license.
● Set temporary password.
● Ensure MFA is enabled and user completes MFA setup.

Device Preparation

● Update Windows.
● Install required software.
● Enable antivirus and disk encryption.

Security Setup
● Enable MFA.
● Apply endpoint protection.
● Assign least-privilege access.

Access Setup

● Verify email, Teams, and OneDrive.


● Add user to required Teams.

First-Day Check (User Handover)

● User can log in successfully.


● MFA works correctly.
● User knows IT contact information.

BONUS – Top 3 IT Risks in Remote Teams


1. Account Compromise
○ Use MFA and strong passwords.
2. Data Loss
○ Use regular backups.
3. Unsecured Devices
○ Use antivirus and device security policies.

You might also like