4.5 KiB
4.5 KiB
MVAN Enterprises — Risky Sign-in Check — 2026-07-14
Tenant: mvan.onmicrosoft.com (5affaf1e-de89-416b-a655-1b2cf615d5b1), domain mvaninc.com Requested by: Mike (Discord thread 1526651647214882956), context: ticket #32554 (mailbox re-sync symptoms) — ruling out account compromise. Tier used: investigator (read-only, cert auth). Window: sign-ins 2026-06-30 → 2026-07-14 (126 events).
Verdict
No evidence of compromise. Zero successful anomalous/foreign sign-ins in the window. All successful sign-ins are consistent US locations (Boise ID home ISP prefix 2605:59ca for June/Mitch; Jason from Oklahoma City; tocurtis@cox.net from Ashburn VA). Identity Protection: 0 active risk detections.
BUT: mitch.v@mvaninc.com is under an active, ongoing distributed credential attack.
Findings
1. Credential-stuffing / password-spray against Mitch (ongoing)
- mitch.v@mvaninc.com: 77 sign-in events, 72 failures from 73 unique IPs across US, CA, DE, IT, RO, NL. Errors: 50053 (sign-in blocked / smart lockout) and 50126 (bad password). Attempts continuing through today (last 2026-07-14 11:57 UTC).
- m.vandeveer@modernstile.com (Mitch's second account, same tenant): 14 attempts, all failed, from JP, NL, NP — latest 2026-07-14 18:57 UTC.
- Every attack attempt FAILED. Mitch's real sign-ins (Boise) succeeded normally.
- Mitch's password was already reset 2026-05-18 (riskState remediated, userPerformedSecuredPasswordReset).
2. MFA posture
| Account | MFA registered |
|---|---|
| mitch.v@mvaninc.com | YES (Hello, Authenticator push, OTP, phone, email) |
| june.b@mvaninc.com | YES |
| jason.r@mvaninc.com | YES |
| sienna.v@mvaninc.com | YES |
| sysadmin@mvaninc.com | YES |
| m.vandeveer@modernstile.com | NO — and actively targeted |
| kyeri.b@mvaninc.com | NO |
| invoicing@mvaninc.com | NO |
| j.bradford@modernstile.com | NO |
3. Stale risky-user record
- j.bradford@modernstile.com: riskLevel medium / atRisk — last updated 2020-12-25 (stale, pre-dates current management; candidate for dismissal after MFA is fixed).
Recommendations
- Register/enforce MFA on the 4 uncovered accounts — priority m.vandeveer@modernstile.com (actively targeted, no MFA). If modernstile accounts are unused, disable them.
- Consider CA policy blocking legacy auth / requiring MFA tenant-wide (report-only first, break-glass excluded).
- The attack is being absorbed by smart lockout + MFA; repeated 50053 lockouts can occasionally cause auth prompts / sync stalls on Mitch's Outlook — possibly related to the ticket #32554 symptoms on his machine, worth noting during troubleshooting.
- Dismiss the stale 2020 risky-user record once MFA is addressed.
Remediation performed (2026-07-14, approved by Mike via Discord)
- Disabled
m.vandeveer@modernstile.com(never a successful sign-in, unlicensed, no MFA, actively targeted) — PATCH accountEnabled=false, verified. - Disabled
j.bradford@modernstile.com(never a successful sign-in, unlicensed, no MFA) — verified. This also moots the stale 2020 risky-user record on this account. - Findings posted to Syncro #32554 as internal comment (id 423730614).
- Account status detail: kyeri.b@mvaninc.com ACTIVE (successful sign-in 2026-07-14 05:10 UTC, licensed) — needs MFA enrollment. invoicing@mvaninc.com dormant since 2025-09-24 (licensed) — disable-or-MFA decision pending.
Consent refresh + CA policy (2026-07-14, later same day)
- Mike re-consented the Tenant Admin app interactively — token now carries the full manifest (Policy.Read.All, Sites.FullControl.All, Intune scopes, etc.). Consent-audit AMBER resolved for tenant-admin. (Exchange Operator re-consent URL was also provided; verify on next EXO task.)
- Created CA policy "ACG - Require MFA for all users (report-only)"
(id
f69d7b41-bf13-4631-b1cd-ccf449ef06b9), stateenabledForReportingButNotEnforced, all users / all apps, grant = MFA, exclude break-glasssysadmin@mvaninc.com(547852a1-4ced-4e36-abe5-52779a53b4b1). Security defaults confirmed off. Pre-existing policies: only the 2 Microsoft-managed ones (device-code block, risky-sign-in MFA). - NEXT: review report-only impact in Entra sign-in logs after a few days of traffic; get
explicit confirmation before flipping to
enabled. kyeri.b and invoicing must enroll MFA before enforcement or they will be blocked.
Artifacts
- Raw sign-ins JSON:
.mvan-signins.json(scripts scratch dir, 14-day window) - Related: Syncro ticket #32554 — https://computerguru.syncromsp.com/tickets/113827636