Files
claudetools/clients/mvan-inc/reports/2026-07-14-risky-signin-check.md
Winter Williams a9a17f426f sync: auto-sync from GURU-BEAST-ROG at 2026-07-14 15:28:42
Author: Mike Swanson
Machine: GURU-BEAST-ROG
Timestamp: 2026-07-14 15:28:42
2026-07-14 15:29:37 -07:00

4.5 KiB

MVAN Enterprises — Risky Sign-in Check — 2026-07-14

Tenant: mvan.onmicrosoft.com (5affaf1e-de89-416b-a655-1b2cf615d5b1), domain mvaninc.com Requested by: Mike (Discord thread 1526651647214882956), context: ticket #32554 (mailbox re-sync symptoms) — ruling out account compromise. Tier used: investigator (read-only, cert auth). Window: sign-ins 2026-06-30 → 2026-07-14 (126 events).

Verdict

No evidence of compromise. Zero successful anomalous/foreign sign-ins in the window. All successful sign-ins are consistent US locations (Boise ID home ISP prefix 2605:59ca for June/Mitch; Jason from Oklahoma City; tocurtis@cox.net from Ashburn VA). Identity Protection: 0 active risk detections.

BUT: mitch.v@mvaninc.com is under an active, ongoing distributed credential attack.

Findings

1. Credential-stuffing / password-spray against Mitch (ongoing)

  • mitch.v@mvaninc.com: 77 sign-in events, 72 failures from 73 unique IPs across US, CA, DE, IT, RO, NL. Errors: 50053 (sign-in blocked / smart lockout) and 50126 (bad password). Attempts continuing through today (last 2026-07-14 11:57 UTC).
  • m.vandeveer@modernstile.com (Mitch's second account, same tenant): 14 attempts, all failed, from JP, NL, NP — latest 2026-07-14 18:57 UTC.
  • Every attack attempt FAILED. Mitch's real sign-ins (Boise) succeeded normally.
  • Mitch's password was already reset 2026-05-18 (riskState remediated, userPerformedSecuredPasswordReset).

2. MFA posture

Account MFA registered
mitch.v@mvaninc.com YES (Hello, Authenticator push, OTP, phone, email)
june.b@mvaninc.com YES
jason.r@mvaninc.com YES
sienna.v@mvaninc.com YES
sysadmin@mvaninc.com YES
m.vandeveer@modernstile.com NO — and actively targeted
kyeri.b@mvaninc.com NO
invoicing@mvaninc.com NO
j.bradford@modernstile.com NO

3. Stale risky-user record

  • j.bradford@modernstile.com: riskLevel medium / atRisk — last updated 2020-12-25 (stale, pre-dates current management; candidate for dismissal after MFA is fixed).

Recommendations

  1. Register/enforce MFA on the 4 uncovered accounts — priority m.vandeveer@modernstile.com (actively targeted, no MFA). If modernstile accounts are unused, disable them.
  2. Consider CA policy blocking legacy auth / requiring MFA tenant-wide (report-only first, break-glass excluded).
  3. The attack is being absorbed by smart lockout + MFA; repeated 50053 lockouts can occasionally cause auth prompts / sync stalls on Mitch's Outlook — possibly related to the ticket #32554 symptoms on his machine, worth noting during troubleshooting.
  4. Dismiss the stale 2020 risky-user record once MFA is addressed.

Remediation performed (2026-07-14, approved by Mike via Discord)

  • Disabled m.vandeveer@modernstile.com (never a successful sign-in, unlicensed, no MFA, actively targeted) — PATCH accountEnabled=false, verified.
  • Disabled j.bradford@modernstile.com (never a successful sign-in, unlicensed, no MFA) — verified. This also moots the stale 2020 risky-user record on this account.
  • Findings posted to Syncro #32554 as internal comment (id 423730614).
  • Account status detail: kyeri.b@mvaninc.com ACTIVE (successful sign-in 2026-07-14 05:10 UTC, licensed) — needs MFA enrollment. invoicing@mvaninc.com dormant since 2025-09-24 (licensed) — disable-or-MFA decision pending.
  • Mike re-consented the Tenant Admin app interactively — token now carries the full manifest (Policy.Read.All, Sites.FullControl.All, Intune scopes, etc.). Consent-audit AMBER resolved for tenant-admin. (Exchange Operator re-consent URL was also provided; verify on next EXO task.)
  • Created CA policy "ACG - Require MFA for all users (report-only)" (id f69d7b41-bf13-4631-b1cd-ccf449ef06b9), state enabledForReportingButNotEnforced, all users / all apps, grant = MFA, exclude break-glass sysadmin@mvaninc.com (547852a1-4ced-4e36-abe5-52779a53b4b1). Security defaults confirmed off. Pre-existing policies: only the 2 Microsoft-managed ones (device-code block, risky-sign-in MFA).
  • NEXT: review report-only impact in Entra sign-in logs after a few days of traffic; get explicit confirmation before flipping to enabled. kyeri.b and invoicing must enroll MFA before enforcement or they will be blocked.

Artifacts