sync: auto-sync from GURU-BEAST-ROG at 2026-07-14 15:28:42
Author: Mike Swanson Machine: GURU-BEAST-ROG Timestamp: 2026-07-14 15:28:42
This commit is contained in:
committed by
ClaudeTools Bot
parent
088ffb7645
commit
a9a17f426f
83
clients/mvan-inc/reports/2026-07-14-risky-signin-check.md
Normal file
83
clients/mvan-inc/reports/2026-07-14-risky-signin-check.md
Normal file
@@ -0,0 +1,83 @@
|
||||
# MVAN Enterprises — Risky Sign-in Check — 2026-07-14
|
||||
|
||||
Tenant: mvan.onmicrosoft.com (5affaf1e-de89-416b-a655-1b2cf615d5b1), domain mvaninc.com
|
||||
Requested by: Mike (Discord thread 1526651647214882956), context: ticket #32554 (mailbox
|
||||
re-sync symptoms) — ruling out account compromise.
|
||||
Tier used: investigator (read-only, cert auth). Window: sign-ins 2026-06-30 → 2026-07-14 (126 events).
|
||||
|
||||
## Verdict
|
||||
|
||||
**No evidence of compromise.** Zero successful anomalous/foreign sign-ins in the window.
|
||||
All successful sign-ins are consistent US locations (Boise ID home ISP prefix 2605:59ca for
|
||||
June/Mitch; Jason from Oklahoma City; tocurtis@cox.net from Ashburn VA). Identity Protection:
|
||||
0 active risk detections.
|
||||
|
||||
**BUT: mitch.v@mvaninc.com is under an active, ongoing distributed credential attack.**
|
||||
|
||||
## Findings
|
||||
|
||||
### 1. Credential-stuffing / password-spray against Mitch (ongoing)
|
||||
- mitch.v@mvaninc.com: 77 sign-in events, **72 failures from 73 unique IPs** across US, CA,
|
||||
DE, IT, RO, NL. Errors: 50053 (sign-in blocked / smart lockout) and 50126 (bad password).
|
||||
Attempts continuing through today (last 2026-07-14 11:57 UTC).
|
||||
- m.vandeveer@modernstile.com (Mitch's second account, same tenant): 14 attempts, all failed,
|
||||
from JP, NL, NP — latest 2026-07-14 18:57 UTC.
|
||||
- Every attack attempt FAILED. Mitch's real sign-ins (Boise) succeeded normally.
|
||||
- Mitch's password was already reset 2026-05-18 (riskState remediated,
|
||||
userPerformedSecuredPasswordReset).
|
||||
|
||||
### 2. MFA posture
|
||||
| Account | MFA registered |
|
||||
|---|---|
|
||||
| mitch.v@mvaninc.com | YES (Hello, Authenticator push, OTP, phone, email) |
|
||||
| june.b@mvaninc.com | YES |
|
||||
| jason.r@mvaninc.com | YES |
|
||||
| sienna.v@mvaninc.com | YES |
|
||||
| sysadmin@mvaninc.com | YES |
|
||||
| **m.vandeveer@modernstile.com** | **NO — and actively targeted** |
|
||||
| **kyeri.b@mvaninc.com** | **NO** |
|
||||
| **invoicing@mvaninc.com** | **NO** |
|
||||
| **j.bradford@modernstile.com** | **NO** |
|
||||
|
||||
### 3. Stale risky-user record
|
||||
- j.bradford@modernstile.com: riskLevel medium / atRisk — last updated 2020-12-25 (stale,
|
||||
pre-dates current management; candidate for dismissal after MFA is fixed).
|
||||
|
||||
## Recommendations
|
||||
1. Register/enforce MFA on the 4 uncovered accounts — priority m.vandeveer@modernstile.com
|
||||
(actively targeted, no MFA). If modernstile accounts are unused, disable them.
|
||||
2. Consider CA policy blocking legacy auth / requiring MFA tenant-wide (report-only first,
|
||||
break-glass excluded).
|
||||
3. The attack is being absorbed by smart lockout + MFA; repeated 50053 lockouts can
|
||||
occasionally cause auth prompts / sync stalls on Mitch's Outlook — possibly related to
|
||||
the ticket #32554 symptoms on his machine, worth noting during troubleshooting.
|
||||
4. Dismiss the stale 2020 risky-user record once MFA is addressed.
|
||||
|
||||
## Remediation performed (2026-07-14, approved by Mike via Discord)
|
||||
|
||||
- **Disabled** `m.vandeveer@modernstile.com` (never a successful sign-in, unlicensed, no MFA,
|
||||
actively targeted) — PATCH accountEnabled=false, verified.
|
||||
- **Disabled** `j.bradford@modernstile.com` (never a successful sign-in, unlicensed, no MFA) —
|
||||
verified. This also moots the stale 2020 risky-user record on this account.
|
||||
- Findings posted to Syncro #32554 as internal comment (id 423730614).
|
||||
- Account status detail: kyeri.b@mvaninc.com ACTIVE (successful sign-in 2026-07-14 05:10 UTC,
|
||||
licensed) — needs MFA enrollment. invoicing@mvaninc.com dormant since 2025-09-24 (licensed) —
|
||||
disable-or-MFA decision pending.
|
||||
|
||||
## Consent refresh + CA policy (2026-07-14, later same day)
|
||||
|
||||
- Mike re-consented the Tenant Admin app interactively — token now carries the full manifest
|
||||
(Policy.Read.All, Sites.FullControl.All, Intune scopes, etc.). Consent-audit AMBER resolved
|
||||
for tenant-admin. (Exchange Operator re-consent URL was also provided; verify on next EXO task.)
|
||||
- Created CA policy **"ACG - Require MFA for all users (report-only)"**
|
||||
(id `f69d7b41-bf13-4631-b1cd-ccf449ef06b9`), state `enabledForReportingButNotEnforced`,
|
||||
all users / all apps, grant = MFA, exclude break-glass `sysadmin@mvaninc.com`
|
||||
(547852a1-4ced-4e36-abe5-52779a53b4b1). Security defaults confirmed off. Pre-existing
|
||||
policies: only the 2 Microsoft-managed ones (device-code block, risky-sign-in MFA).
|
||||
- NEXT: review report-only impact in Entra sign-in logs after a few days of traffic; get
|
||||
explicit confirmation before flipping to `enabled`. kyeri.b and invoicing must enroll MFA
|
||||
before enforcement or they will be blocked.
|
||||
|
||||
## Artifacts
|
||||
- Raw sign-ins JSON: `.mvan-signins.json` (scripts scratch dir, 14-day window)
|
||||
- Related: Syncro ticket #32554 — https://computerguru.syncromsp.com/tickets/113827636
|
||||
Reference in New Issue
Block a user