If you are a Cloud Platform subscriber, review the following steps to secure your websites after an employee’s departure:
Remove the employee from your Acquia Teams
The subscription administrator (glossary term, activate to view definition) should remove the employee from all teams. If the administrator is the departing employee, the departing employee can designate a new organization owner. If this isn’t possible, create a Support ticket and copy the previous owner (glossary term, activate to view definition) on the ticket for an easier transition, if possible. If the previous owner is unavailable, see Transferring ownership from an unavailable owner.
Remove the employee from any elevated roles on your websites
Check any single sign-on solutions your organization (glossary term, activate to view definition) uses.
Remove the employee’s entries from the Teams and Permissions pages
For information about how to do this, see Transferring ownership of an organization. For information about completely deleting a user account from Cloud Platform, see GDPR Data Subject Rights requests.
Update credentials in Pipelines
Pipelines performs jobs with the credentials of the user who first performs a Pipelines job for that subscription. If the departing employee provided the credentials for your subscription, your Pipelines jobs may fail.
Be sure to review the following items to secure your website after an employee’s departure:
Change any administrative passwords to which the employee had access
Affected passwords can include the website itself, shell accounts, and phpMyAdmin.
Review the Drupal roles and permissions
Edit the employee’s account in your Drupal website, and change their access to a lower permission level, or set it to blocked.
Review recent code changes
If the parting is less than amicable, a departing individual may commit code allowing continued access to the website through a back door.
Change the salt for your encryption
For more information about encryption salting, see this Wikipedia article.
If this content did not answer your questions, try searching or contacting our support team for further assistance.
If you are a Cloud Platform subscriber, review the following steps to secure your websites after an employee’s departure:
Remove the employee from your Acquia Teams
The subscription administrator (glossary term, activate to view definition) should remove the employee from all teams. If the administrator is the departing employee, the departing employee can designate a new organization owner. If this isn’t possible, create a Support ticket and copy the previous owner (glossary term, activate to view definition) on the ticket for an easier transition, if possible. If the previous owner is unavailable, see Transferring ownership from an unavailable owner.
Remove the employee from any elevated roles on your websites
Check any single sign-on solutions your organization (glossary term, activate to view definition) uses.
Remove the employee’s entries from the Teams and Permissions pages
For information about how to do this, see Transferring ownership of an organization. For information about completely deleting a user account from Cloud Platform, see GDPR Data Subject Rights requests.
Update credentials in Pipelines
Pipelines performs jobs with the credentials of the user who first performs a Pipelines job for that subscription. If the departing employee provided the credentials for your subscription, your Pipelines jobs may fail.
Be sure to review the following items to secure your website after an employee’s departure:
Change any administrative passwords to which the employee had access
Affected passwords can include the website itself, shell accounts, and phpMyAdmin.
Review the Drupal roles and permissions
Edit the employee’s account in your Drupal website, and change their access to a lower permission level, or set it to blocked.
Review recent code changes
If the parting is less than amicable, a departing individual may commit code allowing continued access to the website through a back door.
Change the salt for your encryption
For more information about encryption salting, see this Wikipedia article.
Click Users and SSH Keys.
This displays the Users and keys page.
Click Users and SSH Keys.
This displays the Users and keys page.
If this content did not answer your questions, try searching or contacting our support team for further assistance.