sync: auto-sync from GURU-BEAST-ROG at 2026-07-21 10:26:01
Author: Mike Swanson Machine: GURU-BEAST-ROG Timestamp: 2026-07-21 10:26:01
This commit is contained in:
@@ -1 +0,0 @@
|
|||||||
{"@odata.context":"https://graph.microsoft.com/v1.0/$metadata#users(id,displayName,userPrincipalName,accountEnabled)","value":[{"id":"9c49a2c1-28aa-4116-aed0-53704ad55208","displayName":"admin","userPrincipalName":"admin@mvan.onmicrosoft.com","accountEnabled":true},{"id":"b82cf38a-7cc7-434e-ba12-f4ad745ac19a","displayName":"Info@modernstile.com","userPrincipalName":"info@mvan.onmicrosoft.com","accountEnabled":true},{"id":"c26c43ab-b3c4-4543-836d-f6d736eaa394","displayName":"MVAN Invoicing","userPrincipalName":"invoicing@mvaninc.com","accountEnabled":true},{"id":"d664c34c-3867-42d7-b33e-aa23775c18f5","displayName":"June MS","userPrincipalName":"j.bradford@modernstile.com","accountEnabled":false},{"id":"17d0969e-ca5b-4b31-8919-6f7d20b07f28","displayName":"Jason Real","userPrincipalName":"jason.r@mvaninc.com","accountEnabled":true},{"id":"44d3538f-4bdb-444c-9f84-2d9f49c34c75","displayName":"June Bradford","userPrincipalName":"june.b@mvaninc.com","accountEnabled":true},{"id":"47d7d4b9-e4fc-4fa7-9f65-da724c2e049f","displayName":"June_Admin","userPrincipalName":"june@mvan.onmicrosoft.com","accountEnabled":true},{"id":"7d6ecbef-d787-4453-aab2-23e8d2806f8d","displayName":"Kyeri Brooks","userPrincipalName":"kyeri.b@mvaninc.com","accountEnabled":true},{"id":"a38fa3e7-9e77-4864-8213-62bb47cce07b","displayName":"Mitch MS","userPrincipalName":"m.vandeveer@modernstile.com","accountEnabled":false},{"id":"149e8f5a-e412-4a33-8f2a-25cdd6a38ad9","displayName":"Mitch VanDeveer","userPrincipalName":"mitch.v@mvaninc.com","accountEnabled":true},{"id":"208c20b1-b57a-4967-b9b7-2bd8f397ec95","displayName":"Mitch_Admin","userPrincipalName":"mitch@mvan.onmicrosoft.com","accountEnabled":true},{"id":"46407841-55aa-45d1-8959-205e22077238","displayName":"Ryan Clark","userPrincipalName":"ryan@mvan.onmicrosoft.com","accountEnabled":true},{"id":"f7ae5b00-4379-4a9d-943b-1337be041b6a","displayName":"Sienna VanDeveer","userPrincipalName":"sienna.v@mvaninc.com","accountEnabled":true},{"id":"547852a1-4ced-4e36-abe5-52779a53b4b1","displayName":"Computer Guru","userPrincipalName":"sysadmin@mvaninc.com","accountEnabled":true},{"id":"6b475028-fcba-4899-a619-be687f6eb2f6","displayName":"tocurtis","userPrincipalName":"tocurtis_cox.net#EXT#@mvan.onmicrosoft.com","accountEnabled":true}]}
|
|
||||||
@@ -1 +0,0 @@
|
|||||||
3e89294b-c519-4e07-968d-88619ccd60fe
|
|
||||||
@@ -0,0 +1,144 @@
|
|||||||
|
# MVAN — Risky Sign-in Alerts Investigation + US Geo-block CA Policy
|
||||||
|
|
||||||
|
## User
|
||||||
|
- **Executed by:** ClaudeTools Discord Bot (GURU-BEAST-ROG)
|
||||||
|
- **Requested by:** Mike Swanson (@azcomputerguru, via Discord) - admin
|
||||||
|
- **Role:** automation (acting on the requester's behalf)
|
||||||
|
|
||||||
|
## Session Summary
|
||||||
|
|
||||||
|
Mike reported via Discord that June (MVAN) was receiving "Risky" alerts and asked for a
|
||||||
|
365 check. Ran the remediation-tool workflow against tenant mvan.onmicrosoft.com
|
||||||
|
(5affaf1e-de89-416b-a655-1b2cf615d5b1). Consent audit graded AMBER (exchange-op missing
|
||||||
|
Mail.ReadWrite; SharePoint app-only role missing) but investigator tier was fully green,
|
||||||
|
sufficient for the whole job. Ten-point breach check on june.b@mvaninc.com came back
|
||||||
|
clean: no active risk (prior risk remediated 2026-01-27 alongside a password change),
|
||||||
|
0 risk detections, 56/56 successful interactive sign-ins all US (Boise/Seattle/Walla
|
||||||
|
Walla/Maple Valley travel pattern), benign inbox rules only, no forwarding, no non-SELF
|
||||||
|
mailbox permissions, MFA intact (Authenticator iPhone 16 Pro Max + WHfB + phone).
|
||||||
|
|
||||||
|
Mailbox search revealed what June actually receives: "Microsoft Entra ID Protection
|
||||||
|
Weekly Digest" from MSSecurity-noreply@microsoft.com, which she forwards to Winter
|
||||||
|
(wwilliams@azcomputerguru.com). The Jul 14 digest reported 0 new risky users and 8 new
|
||||||
|
risky sign-ins. Pulling risky sign-ins tenant-wide exposed the real driver: a sustained
|
||||||
|
password-spray campaign against mitch.v@mvaninc.com and m.vandeveer@modernstile.com
|
||||||
|
(disabled) — 21 medium-risk detections since Jun 22 from JP/NL/FR/IT/RO/NP and US proxy
|
||||||
|
IPs. Separately, a stale riskyUser record on disabled account j.bradford@modernstile.com
|
||||||
|
(medium/atRisk since 2020-12-25) was dismissed on Mike's YES (POST riskyUsers/dismiss,
|
||||||
|
HTTP 204; Entra state read-back lags — re-check later).
|
||||||
|
|
||||||
|
Mike asked whether any spray attempt cleared the password stage (compromise test). Full
|
||||||
|
error-code analysis across 272 failed foreign attempts: 18x 50126 (wrong password), 178x
|
||||||
|
50053 (smart lockout), 76x 50053 (malicious-IP block), and ZERO occurrences of
|
||||||
|
50074/50076/500121 (MFA-stage codes). No foreign attempt ever reached an MFA prompt; all
|
||||||
|
5 successful sign-ins in the window were Mitch's own Boise IPv6. Verdict: no evidence
|
||||||
|
Mitch's password is compromised — blind spray, not credential use. Caveat noted: 50053
|
||||||
|
during lockout masks password correctness, but the overall pattern is conclusive enough.
|
||||||
|
|
||||||
|
Mike directed CA hardening ("Premium licenses support that" — confirmed: 6x Business
|
||||||
|
Premium = Entra P1). Created named location "ACG - Allowed Countries (US)" and CA policy
|
||||||
|
"ACG - Block sign-ins outside US" (block, all users/apps, excludes break-glass
|
||||||
|
admin@mvan.onmicrosoft.com + sysadmin@mvaninc.com), report-only first per skill
|
||||||
|
discipline. Impact verification: all 95 successful tenant-wide sign-ins in the last ~30
|
||||||
|
days were US — zero legit impact. On Mike's YES, flipped to enforced at 2026-07-21
|
||||||
|
17:16Z (10:16 AZ). Also answered a licensing question (SKU inventory below).
|
||||||
|
|
||||||
|
Closed with a new Syncro ticket #32572 (public comment with email on, findings +
|
||||||
|
changes + international-travel notification requirement added at Mike's request),
|
||||||
|
billed 0.5 hr remote against MVAN's prepay block (16.75 -> 16.25), invoice #68060 at
|
||||||
|
$0.00, ticket marked Invoiced, bot alert posted.
|
||||||
|
|
||||||
|
## Key Decisions
|
||||||
|
|
||||||
|
- Used investigator tier only for all reads (least privilege); tenant-admin only for CA
|
||||||
|
writes. Skipped exchange-op re-consent — not needed for this task.
|
||||||
|
- Dismissed the stale j.bradford risk rather than leaving it: account disabled, detection
|
||||||
|
from 2020, and it was a candidate source of recurring "risky user" noise.
|
||||||
|
- Geo-block chosen over password rotation as primary hardening: 30 days of sign-in data
|
||||||
|
showed 100% US legit traffic, making a US-only policy zero-impact; rotation offered but
|
||||||
|
not mandated since no evidence of password compromise.
|
||||||
|
- Excluded sysadmin@mvaninc.com from the CA policy in addition to break-glass — prevents
|
||||||
|
ACG management lockout; both are US-based anyway.
|
||||||
|
- Honest caveat given to Mike: Identity Protection evaluates risk pre-CA, so digests may
|
||||||
|
still count blocked foreign attempts; spray typically tapers once hard-blocked.
|
||||||
|
- Ticket comment tone set to "preventive hardening, no breach" per the compromise
|
||||||
|
analysis — this was the explicit purpose of the password-stage investigation.
|
||||||
|
|
||||||
|
## Problems Encountered
|
||||||
|
|
||||||
|
- `investigator` riskDetections query returned 0 rows despite digest citing 8 risky
|
||||||
|
sign-ins — real-time sign-in risk lives on the signIns log (riskLevelDuringSignIn),
|
||||||
|
not always in riskDetections. Queried auditLogs/signIns filtered on
|
||||||
|
riskLevelDuringSignIn ne 'none' to get the real list.
|
||||||
|
- riskyUsers/dismiss returned 204 but GET still shows atRisk — Entra propagation lag
|
||||||
|
(can take minutes-hours). Needs a later re-check; not retried per API discipline.
|
||||||
|
- CA policy PATCH to enabled returned 204 but immediate read-back showed report-only —
|
||||||
|
replication lag; second read confirmed `enabled`. No re-PATCH needed.
|
||||||
|
- PreToolUse hook blocked writing a token to /tmp path (block-tmp-path.sh) — switched to
|
||||||
|
repo-root path for the tenant-admin token cache. Known Windows /tmp rule.
|
||||||
|
- jq `\s` escape error in gsub — used `[[:space:]]` class instead; digest HTML also
|
||||||
|
needed a Python strip pass to remove the style block.
|
||||||
|
|
||||||
|
## Configuration Changes
|
||||||
|
|
||||||
|
- **MVAN Entra tenant (5affaf1e-de89-416b-a655-1b2cf615d5b1):**
|
||||||
|
- Dismissed riskyUser d664c34c-3867-42d7-b33e-aa23775c18f5 (j.bradford@modernstile.com)
|
||||||
|
- Created countryNamedLocation `1e1aa693-e11b-4493-b007-46263a87c2ee`
|
||||||
|
"ACG - Allowed Countries (US)" (US only, unknown countries NOT included)
|
||||||
|
- Created CA policy `eb638c8d-bd0f-4e6f-aaa6-defbb1aa987f` "ACG - Block sign-ins
|
||||||
|
outside US" — block, includeUsers All, excludeUsers [9c49a2c1-28aa-4116-aed0-53704ad55208
|
||||||
|
(admin@mvan.onmicrosoft.com break-glass), 547852a1-4ced-4e36-abe5-52779a53b4b1
|
||||||
|
(sysadmin@mvaninc.com)], all apps, includeLocations All / excludeLocations [the US
|
||||||
|
named location]. Created report-only, flipped to **enabled** 2026-07-21T17:16:17Z.
|
||||||
|
- No repo file changes beyond this session log and transient scratch JSON (./.mvan-*.json,
|
||||||
|
./.mvan-ta.jwt — safe to delete).
|
||||||
|
|
||||||
|
## Credentials & Secrets
|
||||||
|
|
||||||
|
- Vault paths read (values not recorded here): `clients/mvan-inc/m365.sops.yaml` (tenant
|
||||||
|
global admin sysadmin@mvaninc.com), MSP app certs via remediation-tool get-token.sh
|
||||||
|
(investigator, tenant-admin tiers). Syncro key via syncro-env.sh (mike).
|
||||||
|
- No new credentials created.
|
||||||
|
|
||||||
|
## Infrastructure & Servers
|
||||||
|
|
||||||
|
- Tenant: mvan.onmicrosoft.com = 5affaf1e-de89-416b-a655-1b2cf615d5b1 (MVAN Enterprises)
|
||||||
|
- Secondary domain: modernstile.com (same tenant); jemaenterprises.com refs in old risk data
|
||||||
|
- Existing CA policies pre-change: 2 Microsoft-managed (device code block, MFA for risky
|
||||||
|
sign-ins) + "ACG - Require MFA for all users" (report-only)
|
||||||
|
- M365 licensing: Business Premium 5/6, Business Basic 3/4, Business Standard 0/2 (UNUSED),
|
||||||
|
Windows 365 Ent 4/16/128 0/1 (UNUSED), Entra P2 1/1 (sysadmin — powers Identity
|
||||||
|
Protection), Intune Plan 2 2/2, Project Plan 3 1/1. Flagged unused seats to Mike.
|
||||||
|
|
||||||
|
## Commands & Outputs
|
||||||
|
|
||||||
|
- Breach check: `user-breach-check.sh 5affaf1e-... june.b@mvaninc.com` — all clean.
|
||||||
|
- Risky sign-ins: `GET /auditLogs/signIns?$filter=riskLevelDuringSignIn ne 'none'` — 21
|
||||||
|
medium detections, all vs Mitch's two accounts, all failed.
|
||||||
|
- Compromise test: error-code buckets mitch.v = 183x 50053 / 10x 50126 / 5x success;
|
||||||
|
m.vandeveer = 71x 50053 / 8x 50126. 50053 failureReason split: 178 locked / 76
|
||||||
|
malicious-IP. No 50074/50076/500121 anywhere.
|
||||||
|
- Impact check: `GET /auditLogs/signIns?$filter=status/errorCode eq 0` — 95/95 US.
|
||||||
|
- Raw artifacts: /tmp/remediation-tool/5affaf1e-.../user-breach/june_b_mvaninc_com/
|
||||||
|
|
||||||
|
## Pending / Incomplete Tasks
|
||||||
|
|
||||||
|
- Re-verify j.bradford riskyUser shows dismissed once Entra propagates (was still atRisk
|
||||||
|
at last read ~17:05Z).
|
||||||
|
- Optional (offered, not ordered): rotate mitch.v password as precaution.
|
||||||
|
- Consent audit AMBER items if ever needed: exchange-op re-consent (Mail.ReadWrite),
|
||||||
|
SharePoint app-only Sites.FullControl.All grant.
|
||||||
|
- MVAN unused licenses (2x Business Standard, 1x Windows 365) — candidate cost savings,
|
||||||
|
raise with client at renewal.
|
||||||
|
- MVAN must notify ACG before international travel — CA will block foreign sign-ins
|
||||||
|
(communicated on ticket).
|
||||||
|
|
||||||
|
## Reference Information
|
||||||
|
|
||||||
|
- Syncro ticket #32572 (id 114070866): https://computerguru.syncromsp.com/tickets/114070866
|
||||||
|
- Invoice #68060 (id 1651119968), $0.00, applied 0.5 prepay hrs; block 16.75 -> 16.25
|
||||||
|
- Public comment id 424692208 (emailed to june.b@mvaninc.com); line item id 43354647
|
||||||
|
- CA policy id: eb638c8d-bd0f-4e6f-aaa6-defbb1aa987f; named location id:
|
||||||
|
1e1aa693-e11b-4493-b007-46263a87c2ee
|
||||||
|
- Discord thread: 1529170314129313912 (#admin-chat, kept)
|
||||||
|
- Bot alert message id: 1529177282604826696
|
||||||
Reference in New Issue
Block a user