Nov. 14, 2023, 9:24 p.m. | /u/reencrypt

cybersecurity www.reddit.com

Alright, I'm running into a wall and need some guidance.



We've had a few clients with M365 account compromises recently. Most, if not all have decent controls in place (MFA/Number Matching, Authenticator, GeoIp blocking, Legacy Auth disabled, etc).

Couple things to note:

First obvious suspicious sign-in are coming from within the United States. I tracked a few of the IPs to multiple VPN and/or proxy services, but a lot of them were Microsoft data centers.

The one compromise had …

account auth authenticator blocking clients coming controls cybersecurity disabled etc geoip guidance legacy m365 mfa running sign states things united united states

CyberSOC Technical Lead

@ Integrity360 | Sandyford, Dublin, Ireland

Cyber Security Strategy Consultant

@ Capco | New York City

Cyber Security Senior Consultant

@ Capco | Chicago, IL

Sr. Product Manager

@ MixMode | Remote, US

Corporate Intern - Information Security (Year Round)

@ Associated Bank | US WI Remote

Senior Offensive Security Engineer

@ CoStar Group | US-DC Washington, DC