Learnings

77 active rules the fleet reads at session start. This table wins on conflict.

ProcessActiveCriticalWork - Laptop, Apr 1
NEVER enforce Conditional Access policies without per-policy confirmation

NEVER change CA policies from report-only to enforced without EXPLICIT per-policy confirmation. Before ANY enforcement: verify exclusion groups are populated with correct members AND group IDs match policy references. Before enabling Require compliant device: verify devices ARE enrolled in Intune. Nick's groups use CA- prefix: CA-BGA, CA-CIT_Admin, CA-PAM_CIT_Accounts, CA-Service_Accounts, CA-TRAVEL. Never batch-enforce all policies at once. One at a time, verify access after each. Treat this as a BLOCKING safety check like a destructive operation.

Applies toAllAgentsFritzNadiaAll
ProcessActiveWork - Desktop, Apr 22
SCHARPDB credit card blocker is escalated to Dr. Barbour — don't re-flag

SCHARPDB cloud DB build (Prat Yadav) is blocked on a SCHARP IT credit card being set up. The credit card request is WITH Dr. Jack Barbour (CEO) and he is aware of the blocker. Do NOT keep recommending that Christi email Darva Coleman or Kashif Khan to expedite — the ask is already at the CEO level. Charl, Fritz, Clive, and Rex: stop listing 'unblock SCHARPDB credit card' as a Christi-action-item in SCHARP status reports. Frame it as 'pending with Dr. Barbour, CEO aware' instead. The 15-year-old Dell PowerEdge 2950 running production SQL IS still a real risk, but the mitigation path is already in motion. Only re-raise if: (a) Dr. Barbour signals it's dropped / needs a nudge from Christi, (b) a new DB-dependent project gets blocked by the same delay, or (c) the Dell actually fails.

Applies toSCHARPAgentsCharlFritzCliveRex