Case study

Recovering plugins when the only copy of the source was on a wiped laptop

Source code kept on one person's laptop is one security wipe away from gone.

The challenge

A consulting firm had built a group of Dynamics 365 plugins for one of its customers. The consultant who wrote them had since left the firm, and as standard security practice the firm had wiped that laptop when the employment ended.

The only copy of the source code was on that laptop.

Then the customer found several bugs, and the plugins needed to be fixed.

Two problems, not one

No home for source code

The firm did few programming projects, so it had no facility for tracking and storing source code, for its own work or for customer projects.

No source to fix

Before any bug could be fixed, the source for the plugins had to be recreated from what was left.

What we did

  • Put source control in place first. We walked one of the firm's consultants through signing up for Azure DevOps and created an organization where the firm can store the source for anything it works on.
  • Recovered the source. With credentials to the customer's Dynamics organization, we downloaded the deployed plugin assembly, decompiled it, and spent about two weeks restoring the code to a human-readable state.
  • Fixed and redeployed. With a working codebase back, we fixed the issues the customer had identified and redeployed the corrected plugins to their environment.

The result

~3 weeksfrom start to finish
~2 weeksto restore the source to readable code
1source control organization, set up so it can't happen again

The customer's bugs were fixed and the corrected plugins were running in their own environment. The firm now has a place to keep the source for every project, so the next departure doesn't put its customers' code at risk.

The plugins were never the problem. They kept running the whole time. The only thing that was lost was the ability to change them, and that came back from the deployed assembly.

Why it matters

This scenario is far more common than most firms like to admit. Teams that only occasionally write code rarely have source control, so the code ends up on someone's laptop. Then a sensible, routine security practice, wiping a departed employee's machine, erases the only copy.

The fix isn't weaker security. It's keeping source somewhere that outlasts any one person, and knowing that if it is ever lost, the code running in your environment is the way back.

Is your source safe?

  • Do you know where the source for each custom plugin and workflow activity lives?
  • Is there a copy anywhere other than one person's computer?
  • Would it survive that person leaving tomorrow?
  • Do you know which assemblies in your environment have no source at all?

If the answer to any of these is "no," or "not sure," a Plugin Health Check finds out for you.