sync: auto-sync from GURU-BEAST-ROG at 2026-07-14 15:28:42

Author: Mike Swanson
Machine: GURU-BEAST-ROG
Timestamp: 2026-07-14 15:28:42
This commit is contained in:
Winter Williams
2026-07-14 15:29:34 -07:00
committed by ClaudeTools Bot
parent 088ffb7645
commit a9a17f426f
2 changed files with 124 additions and 0 deletions

View File

@@ -0,0 +1,83 @@
# MVAN Enterprises — Risky Sign-in Check — 2026-07-14
Tenant: mvan.onmicrosoft.com (5affaf1e-de89-416b-a655-1b2cf615d5b1), domain mvaninc.com
Requested by: Mike (Discord thread 1526651647214882956), context: ticket #32554 (mailbox
re-sync symptoms) — ruling out account compromise.
Tier used: investigator (read-only, cert auth). Window: sign-ins 2026-06-30 → 2026-07-14 (126 events).
## Verdict
**No evidence of compromise.** Zero successful anomalous/foreign sign-ins in the window.
All successful sign-ins are consistent US locations (Boise ID home ISP prefix 2605:59ca for
June/Mitch; Jason from Oklahoma City; tocurtis@cox.net from Ashburn VA). Identity Protection:
0 active risk detections.
**BUT: mitch.v@mvaninc.com is under an active, ongoing distributed credential attack.**
## Findings
### 1. Credential-stuffing / password-spray against Mitch (ongoing)
- mitch.v@mvaninc.com: 77 sign-in events, **72 failures from 73 unique IPs** across US, CA,
DE, IT, RO, NL. Errors: 50053 (sign-in blocked / smart lockout) and 50126 (bad password).
Attempts continuing through today (last 2026-07-14 11:57 UTC).
- m.vandeveer@modernstile.com (Mitch's second account, same tenant): 14 attempts, all failed,
from JP, NL, NP — latest 2026-07-14 18:57 UTC.
- Every attack attempt FAILED. Mitch's real sign-ins (Boise) succeeded normally.
- Mitch's password was already reset 2026-05-18 (riskState remediated,
userPerformedSecuredPasswordReset).
### 2. MFA posture
| Account | MFA registered |
|---|---|
| mitch.v@mvaninc.com | YES (Hello, Authenticator push, OTP, phone, email) |
| june.b@mvaninc.com | YES |
| jason.r@mvaninc.com | YES |
| sienna.v@mvaninc.com | YES |
| sysadmin@mvaninc.com | YES |
| **m.vandeveer@modernstile.com** | **NO — and actively targeted** |
| **kyeri.b@mvaninc.com** | **NO** |
| **invoicing@mvaninc.com** | **NO** |
| **j.bradford@modernstile.com** | **NO** |
### 3. Stale risky-user record
- j.bradford@modernstile.com: riskLevel medium / atRisk — last updated 2020-12-25 (stale,
pre-dates current management; candidate for dismissal after MFA is fixed).
## Recommendations
1. Register/enforce MFA on the 4 uncovered accounts — priority m.vandeveer@modernstile.com
(actively targeted, no MFA). If modernstile accounts are unused, disable them.
2. Consider CA policy blocking legacy auth / requiring MFA tenant-wide (report-only first,
break-glass excluded).
3. The attack is being absorbed by smart lockout + MFA; repeated 50053 lockouts can
occasionally cause auth prompts / sync stalls on Mitch's Outlook — possibly related to
the ticket #32554 symptoms on his machine, worth noting during troubleshooting.
4. Dismiss the stale 2020 risky-user record once MFA is addressed.
## Remediation performed (2026-07-14, approved by Mike via Discord)
- **Disabled** `m.vandeveer@modernstile.com` (never a successful sign-in, unlicensed, no MFA,
actively targeted) — PATCH accountEnabled=false, verified.
- **Disabled** `j.bradford@modernstile.com` (never a successful sign-in, unlicensed, no MFA) —
verified. This also moots the stale 2020 risky-user record on this account.
- Findings posted to Syncro #32554 as internal comment (id 423730614).
- Account status detail: kyeri.b@mvaninc.com ACTIVE (successful sign-in 2026-07-14 05:10 UTC,
licensed) — needs MFA enrollment. invoicing@mvaninc.com dormant since 2025-09-24 (licensed) —
disable-or-MFA decision pending.
## Consent refresh + CA policy (2026-07-14, later same day)
- Mike re-consented the Tenant Admin app interactively — token now carries the full manifest
(Policy.Read.All, Sites.FullControl.All, Intune scopes, etc.). Consent-audit AMBER resolved
for tenant-admin. (Exchange Operator re-consent URL was also provided; verify on next EXO task.)
- Created CA policy **"ACG - Require MFA for all users (report-only)"**
(id `f69d7b41-bf13-4631-b1cd-ccf449ef06b9`), state `enabledForReportingButNotEnforced`,
all users / all apps, grant = MFA, exclude break-glass `sysadmin@mvaninc.com`
(547852a1-4ced-4e36-abe5-52779a53b4b1). Security defaults confirmed off. Pre-existing
policies: only the 2 Microsoft-managed ones (device-code block, risky-sign-in MFA).
- NEXT: review report-only impact in Entra sign-in logs after a few days of traffic; get
explicit confirmation before flipping to `enabled`. kyeri.b and invoicing must enroll MFA
before enforcement or they will be blocked.
## Artifacts
- Raw sign-ins JSON: `.mvan-signins.json` (scripts scratch dir, 14-day window)
- Related: Syncro ticket #32554 — https://computerguru.syncromsp.com/tickets/113827636