diff --git a/.mvan-users.json b/.mvan-users.json deleted file mode 100644 index 763dad38..00000000 --- a/.mvan-users.json +++ /dev/null @@ -1 +0,0 @@ -{"@odata.context":"https://graph.microsoft.com/v1.0/$metadata#users(id,displayName,userPrincipalName,accountEnabled)","value":[{"id":"9c49a2c1-28aa-4116-aed0-53704ad55208","displayName":"admin","userPrincipalName":"admin@mvan.onmicrosoft.com","accountEnabled":true},{"id":"b82cf38a-7cc7-434e-ba12-f4ad745ac19a","displayName":"Info@modernstile.com","userPrincipalName":"info@mvan.onmicrosoft.com","accountEnabled":true},{"id":"c26c43ab-b3c4-4543-836d-f6d736eaa394","displayName":"MVAN Invoicing","userPrincipalName":"invoicing@mvaninc.com","accountEnabled":true},{"id":"d664c34c-3867-42d7-b33e-aa23775c18f5","displayName":"June MS","userPrincipalName":"j.bradford@modernstile.com","accountEnabled":false},{"id":"17d0969e-ca5b-4b31-8919-6f7d20b07f28","displayName":"Jason Real","userPrincipalName":"jason.r@mvaninc.com","accountEnabled":true},{"id":"44d3538f-4bdb-444c-9f84-2d9f49c34c75","displayName":"June Bradford","userPrincipalName":"june.b@mvaninc.com","accountEnabled":true},{"id":"47d7d4b9-e4fc-4fa7-9f65-da724c2e049f","displayName":"June_Admin","userPrincipalName":"june@mvan.onmicrosoft.com","accountEnabled":true},{"id":"7d6ecbef-d787-4453-aab2-23e8d2806f8d","displayName":"Kyeri Brooks","userPrincipalName":"kyeri.b@mvaninc.com","accountEnabled":true},{"id":"a38fa3e7-9e77-4864-8213-62bb47cce07b","displayName":"Mitch MS","userPrincipalName":"m.vandeveer@modernstile.com","accountEnabled":false},{"id":"149e8f5a-e412-4a33-8f2a-25cdd6a38ad9","displayName":"Mitch VanDeveer","userPrincipalName":"mitch.v@mvaninc.com","accountEnabled":true},{"id":"208c20b1-b57a-4967-b9b7-2bd8f397ec95","displayName":"Mitch_Admin","userPrincipalName":"mitch@mvan.onmicrosoft.com","accountEnabled":true},{"id":"46407841-55aa-45d1-8959-205e22077238","displayName":"Ryan Clark","userPrincipalName":"ryan@mvan.onmicrosoft.com","accountEnabled":true},{"id":"f7ae5b00-4379-4a9d-943b-1337be041b6a","displayName":"Sienna VanDeveer","userPrincipalName":"sienna.v@mvaninc.com","accountEnabled":true},{"id":"547852a1-4ced-4e36-abe5-52779a53b4b1","displayName":"Computer Guru","userPrincipalName":"sysadmin@mvaninc.com","accountEnabled":true},{"id":"6b475028-fcba-4899-a619-be687f6eb2f6","displayName":"tocurtis","userPrincipalName":"tocurtis_cox.net#EXT#@mvan.onmicrosoft.com","accountEnabled":true}]} \ No newline at end of file diff --git a/.tps_cmd_id b/.tps_cmd_id deleted file mode 100644 index 3d6a0745..00000000 --- a/.tps_cmd_id +++ /dev/null @@ -1 +0,0 @@ -3e89294b-c519-4e07-968d-88619ccd60fe diff --git a/clients/mvan-inc/session-logs/2026-07/2026-07-21-mike-risky-signin-investigation-geoblock.md b/clients/mvan-inc/session-logs/2026-07/2026-07-21-mike-risky-signin-investigation-geoblock.md new file mode 100644 index 00000000..42f1cd9a --- /dev/null +++ b/clients/mvan-inc/session-logs/2026-07/2026-07-21-mike-risky-signin-investigation-geoblock.md @@ -0,0 +1,144 @@ +# MVAN — Risky Sign-in Alerts Investigation + US Geo-block CA Policy + +## User +- **Executed by:** ClaudeTools Discord Bot (GURU-BEAST-ROG) +- **Requested by:** Mike Swanson (@azcomputerguru, via Discord) - admin +- **Role:** automation (acting on the requester's behalf) + +## Session Summary + +Mike reported via Discord that June (MVAN) was receiving "Risky" alerts and asked for a +365 check. Ran the remediation-tool workflow against tenant mvan.onmicrosoft.com +(5affaf1e-de89-416b-a655-1b2cf615d5b1). Consent audit graded AMBER (exchange-op missing +Mail.ReadWrite; SharePoint app-only role missing) but investigator tier was fully green, +sufficient for the whole job. Ten-point breach check on june.b@mvaninc.com came back +clean: no active risk (prior risk remediated 2026-01-27 alongside a password change), +0 risk detections, 56/56 successful interactive sign-ins all US (Boise/Seattle/Walla +Walla/Maple Valley travel pattern), benign inbox rules only, no forwarding, no non-SELF +mailbox permissions, MFA intact (Authenticator iPhone 16 Pro Max + WHfB + phone). + +Mailbox search revealed what June actually receives: "Microsoft Entra ID Protection +Weekly Digest" from MSSecurity-noreply@microsoft.com, which she forwards to Winter +(wwilliams@azcomputerguru.com). The Jul 14 digest reported 0 new risky users and 8 new +risky sign-ins. Pulling risky sign-ins tenant-wide exposed the real driver: a sustained +password-spray campaign against mitch.v@mvaninc.com and m.vandeveer@modernstile.com +(disabled) — 21 medium-risk detections since Jun 22 from JP/NL/FR/IT/RO/NP and US proxy +IPs. Separately, a stale riskyUser record on disabled account j.bradford@modernstile.com +(medium/atRisk since 2020-12-25) was dismissed on Mike's YES (POST riskyUsers/dismiss, +HTTP 204; Entra state read-back lags — re-check later). + +Mike asked whether any spray attempt cleared the password stage (compromise test). Full +error-code analysis across 272 failed foreign attempts: 18x 50126 (wrong password), 178x +50053 (smart lockout), 76x 50053 (malicious-IP block), and ZERO occurrences of +50074/50076/500121 (MFA-stage codes). No foreign attempt ever reached an MFA prompt; all +5 successful sign-ins in the window were Mitch's own Boise IPv6. Verdict: no evidence +Mitch's password is compromised — blind spray, not credential use. Caveat noted: 50053 +during lockout masks password correctness, but the overall pattern is conclusive enough. + +Mike directed CA hardening ("Premium licenses support that" — confirmed: 6x Business +Premium = Entra P1). Created named location "ACG - Allowed Countries (US)" and CA policy +"ACG - Block sign-ins outside US" (block, all users/apps, excludes break-glass +admin@mvan.onmicrosoft.com + sysadmin@mvaninc.com), report-only first per skill +discipline. Impact verification: all 95 successful tenant-wide sign-ins in the last ~30 +days were US — zero legit impact. On Mike's YES, flipped to enforced at 2026-07-21 +17:16Z (10:16 AZ). Also answered a licensing question (SKU inventory below). + +Closed with a new Syncro ticket #32572 (public comment with email on, findings + +changes + international-travel notification requirement added at Mike's request), +billed 0.5 hr remote against MVAN's prepay block (16.75 -> 16.25), invoice #68060 at +$0.00, ticket marked Invoiced, bot alert posted. + +## Key Decisions + +- Used investigator tier only for all reads (least privilege); tenant-admin only for CA + writes. Skipped exchange-op re-consent — not needed for this task. +- Dismissed the stale j.bradford risk rather than leaving it: account disabled, detection + from 2020, and it was a candidate source of recurring "risky user" noise. +- Geo-block chosen over password rotation as primary hardening: 30 days of sign-in data + showed 100% US legit traffic, making a US-only policy zero-impact; rotation offered but + not mandated since no evidence of password compromise. +- Excluded sysadmin@mvaninc.com from the CA policy in addition to break-glass — prevents + ACG management lockout; both are US-based anyway. +- Honest caveat given to Mike: Identity Protection evaluates risk pre-CA, so digests may + still count blocked foreign attempts; spray typically tapers once hard-blocked. +- Ticket comment tone set to "preventive hardening, no breach" per the compromise + analysis — this was the explicit purpose of the password-stage investigation. + +## Problems Encountered + +- `investigator` riskDetections query returned 0 rows despite digest citing 8 risky + sign-ins — real-time sign-in risk lives on the signIns log (riskLevelDuringSignIn), + not always in riskDetections. Queried auditLogs/signIns filtered on + riskLevelDuringSignIn ne 'none' to get the real list. +- riskyUsers/dismiss returned 204 but GET still shows atRisk — Entra propagation lag + (can take minutes-hours). Needs a later re-check; not retried per API discipline. +- CA policy PATCH to enabled returned 204 but immediate read-back showed report-only — + replication lag; second read confirmed `enabled`. No re-PATCH needed. +- PreToolUse hook blocked writing a token to /tmp path (block-tmp-path.sh) — switched to + repo-root path for the tenant-admin token cache. Known Windows /tmp rule. +- jq `\s` escape error in gsub — used `[[:space:]]` class instead; digest HTML also + needed a Python strip pass to remove the style block. + +## Configuration Changes + +- **MVAN Entra tenant (5affaf1e-de89-416b-a655-1b2cf615d5b1):** + - Dismissed riskyUser d664c34c-3867-42d7-b33e-aa23775c18f5 (j.bradford@modernstile.com) + - Created countryNamedLocation `1e1aa693-e11b-4493-b007-46263a87c2ee` + "ACG - Allowed Countries (US)" (US only, unknown countries NOT included) + - Created CA policy `eb638c8d-bd0f-4e6f-aaa6-defbb1aa987f` "ACG - Block sign-ins + outside US" — block, includeUsers All, excludeUsers [9c49a2c1-28aa-4116-aed0-53704ad55208 + (admin@mvan.onmicrosoft.com break-glass), 547852a1-4ced-4e36-abe5-52779a53b4b1 + (sysadmin@mvaninc.com)], all apps, includeLocations All / excludeLocations [the US + named location]. Created report-only, flipped to **enabled** 2026-07-21T17:16:17Z. +- No repo file changes beyond this session log and transient scratch JSON (./.mvan-*.json, + ./.mvan-ta.jwt — safe to delete). + +## Credentials & Secrets + +- Vault paths read (values not recorded here): `clients/mvan-inc/m365.sops.yaml` (tenant + global admin sysadmin@mvaninc.com), MSP app certs via remediation-tool get-token.sh + (investigator, tenant-admin tiers). Syncro key via syncro-env.sh (mike). +- No new credentials created. + +## Infrastructure & Servers + +- Tenant: mvan.onmicrosoft.com = 5affaf1e-de89-416b-a655-1b2cf615d5b1 (MVAN Enterprises) +- Secondary domain: modernstile.com (same tenant); jemaenterprises.com refs in old risk data +- Existing CA policies pre-change: 2 Microsoft-managed (device code block, MFA for risky + sign-ins) + "ACG - Require MFA for all users" (report-only) +- M365 licensing: Business Premium 5/6, Business Basic 3/4, Business Standard 0/2 (UNUSED), + Windows 365 Ent 4/16/128 0/1 (UNUSED), Entra P2 1/1 (sysadmin — powers Identity + Protection), Intune Plan 2 2/2, Project Plan 3 1/1. Flagged unused seats to Mike. + +## Commands & Outputs + +- Breach check: `user-breach-check.sh 5affaf1e-... june.b@mvaninc.com` — all clean. +- Risky sign-ins: `GET /auditLogs/signIns?$filter=riskLevelDuringSignIn ne 'none'` — 21 + medium detections, all vs Mitch's two accounts, all failed. +- Compromise test: error-code buckets mitch.v = 183x 50053 / 10x 50126 / 5x success; + m.vandeveer = 71x 50053 / 8x 50126. 50053 failureReason split: 178 locked / 76 + malicious-IP. No 50074/50076/500121 anywhere. +- Impact check: `GET /auditLogs/signIns?$filter=status/errorCode eq 0` — 95/95 US. +- Raw artifacts: /tmp/remediation-tool/5affaf1e-.../user-breach/june_b_mvaninc_com/ + +## Pending / Incomplete Tasks + +- Re-verify j.bradford riskyUser shows dismissed once Entra propagates (was still atRisk + at last read ~17:05Z). +- Optional (offered, not ordered): rotate mitch.v password as precaution. +- Consent audit AMBER items if ever needed: exchange-op re-consent (Mail.ReadWrite), + SharePoint app-only Sites.FullControl.All grant. +- MVAN unused licenses (2x Business Standard, 1x Windows 365) — candidate cost savings, + raise with client at renewal. +- MVAN must notify ACG before international travel — CA will block foreign sign-ins + (communicated on ticket). + +## Reference Information + +- Syncro ticket #32572 (id 114070866): https://computerguru.syncromsp.com/tickets/114070866 +- Invoice #68060 (id 1651119968), $0.00, applied 0.5 prepay hrs; block 16.75 -> 16.25 +- Public comment id 424692208 (emailed to june.b@mvaninc.com); line item id 43354647 +- CA policy id: eb638c8d-bd0f-4e6f-aaa6-defbb1aa987f; named location id: + 1e1aa693-e11b-4493-b007-46263a87c2ee +- Discord thread: 1529170314129313912 (#admin-chat, kept) +- Bot alert message id: 1529177282604826696