🌐 https://login.microsoftonline.com/\
URL
· host
login.microsoftonline.com
· threat 0.50 (HIGH)
· Threat Reports First seen 2026-08-23 12:47:34 · last seen 2026-08-23 12:47:34
🔄 Pivot:📁 Threat Reports
Threat score
0.50
MEDIUM
Sightings
1
1 sources
Subdomains (local)
0
from indicators
Related IPs
32
A/AAAA records
DNS records (local)
17
3 types
Reporting sources
1
0 enrichments
📡 Reporting-source breakdown
1
1 total source links on this indicator.
🏷 Tag breakdown (domain family)
No data.
📈 DNS record-type counts
8
8
1
📅 First-seen timeline (family)
1
🏷 WHOIS / Registration (local cache)
No cached WHOIS for login.microsoftonline.com. Resolve & cache.
📡 DNS Records
Stored (local dns_records) — 17
| Type | Value | TTL | Checked |
|---|---|---|---|
| A | 20.190.151.9 |
94 | 2026-08-26 |
| A | 20.190.151.67 |
94 | 2026-08-26 |
| A | 20.190.151.134 |
94 | 2026-08-26 |
| A | 20.190.151.133 |
94 | 2026-08-26 |
| A | 20.190.151.132 |
94 | 2026-08-26 |
| A | 20.190.151.131 |
94 | 2026-08-26 |
| A | 20.190.151.70 |
94 | 2026-08-26 |
| A | 20.190.151.68 |
94 | 2026-08-26 |
| AAAA | 2603:1036:3000:f0::2 |
249 | 2026-08-26 |
| AAAA | 2603:1036:3000:e8::4 |
249 | 2026-08-26 |
| AAAA | 2603:1036:3000:f8::4 |
249 | 2026-08-26 |
| AAAA | 2603:1036:3000:e8::2 |
249 | 2026-08-26 |
| AAAA | 2603:1036:3000:f8::2 |
249 | 2026-08-26 |
| AAAA | 2603:1036:3000:e8::3 |
249 | 2026-08-26 |
| AAAA | 2603:1036:3000:f0::4 |
249 | 2026-08-26 |
| AAAA | 2603:1036:3000:f0::1 |
249 | 2026-08-26 |
| CNAME | login.mso.msidentity.com |
1275 | 2026-08-26 |
Live (DNS-over-HTTPS · optional augmentation)
| Type | Value | TTL |
|---|---|---|
| A | login.mso.msidentity.com. |
13511 |
| A | ak.privatelink.msidentity.com. |
171 |
| A | www.tm.a.prd.aadg.akadns.net. |
224 |
| A | 40.126.29.13 |
300 |
| A | 40.126.29.8 |
300 |
| A | 40.126.29.14 |
300 |
| A | 40.126.29.11 |
300 |
| A | 40.126.29.10 |
300 |
| A | 20.190.157.14 |
300 |
| A | 20.190.157.1 |
300 |
| A | 20.190.157.13 |
300 |
| AAAA | login.mso.msidentity.com. |
13674 |
| AAAA | ak.privatelink.msidentity.com. |
158 |
| AAAA | www.tm.a.prd.aadg.akadns.net. |
158 |
| AAAA | 2603:1037:1:60:: |
300 |
| AAAA | 2603:1036:3000:60::20 |
300 |
| AAAA | 2603:1036:3000:60::2 |
300 |
| AAAA | 2603:1036:3000:60::1f |
300 |
| AAAA | 2603:1036:3000:60::11 |
300 |
| AAAA | 2603:1036:3000:60::3 |
300 |
| AAAA | 2603:1036:3000:60::14 |
300 |
| AAAA | 2603:1036:3000:60::15 |
300 |
| MX | login.mso.msidentity.com. |
13412 |
| MX | ak.privatelink.msidentity.com. |
73 |
| MX | www.tm.a.prd.aadg.trafficmanager.net. |
102 |
| NS | login.mso.msidentity.com. |
12873 |
| NS | ak.privatelink.msidentity.com. |
216 |
| NS | www.tm.a.prd.aadg.akadns.net. |
47 |
| TXT | login.mso.msidentity.com. |
13674 |
| TXT | ak.privatelink.msidentity.com. |
158 |
| TXT | www.tm.a.prd.aadg.akadns.net. |
158 |
| CNAME | login.mso.msidentity.com. |
10923 |
🖥 Related IPs (32)
Resolved from local A/AAAA records (augmented with live DoH when reachable). Each pivots to its IP dossier.
20.190.151.9 →
20.190.151.67 →
20.190.151.134 →
20.190.151.133 →
20.190.151.132 →
20.190.151.131 →
20.190.151.70 →
20.190.151.68 →
2603:1036:3000:f0::2 →
2603:1036:3000:e8::4 →
2603:1036:3000:f8::4 →
2603:1036:3000:e8::2 →
2603:1036:3000:f8::2 →
2603:1036:3000:e8::3 →
2603:1036:3000:f0::4 →
2603:1036:3000:f0::1 →
40.126.29.13 →
40.126.29.8 →
40.126.29.14 →
40.126.29.11 →
40.126.29.10 →
20.190.157.14 →
20.190.157.1 →
20.190.157.13 →
2603:1037:1:60:: →
2603:1036:3000:60::20 →
2603:1036:3000:60::2 →
2603:1036:3000:60::1f →
2603:1036:3000:60::11 →
2603:1036:3000:60::3 →
2603:1036:3000:60::14 →
2603:1036:3000:60::15 →
🌐 Subdomains — local intel (0)
No subdomains of login.microsoftonline.com in local intel. Check crt.sh ↗
📡 Reporting Sources (1)
ORKL Threat Reports API | Threat Reports |
🌐 Same-ASN domains (0)
No ASN linkage in local intel.
🔍 OSINT pivots — external lookups
🔗 Internal pivots & actions
📁 Case Management
Every panel resolves local-first: threat, category, first-seen & sightings from
indicators; DNS from dns_records; WHOIS from whois_cache; subdomains via bounded suffix match on indicators; related IPs from A/AAAA records; tags, reporting sources and the link graph from the local relations. Live OTX pulses and DNS-over-HTTPS are optional augmentation and their absence never blanks the dossier.
Workstation · Copilot · AI Skills · Automation · Playbooks · Lookups · Docs · Reports
🤖 AI Copilot
⚡ AI Skills
🔍 Lookup & Enrich
📚 Docs & Reports
💡 Recommendations
- Audit DNS to build passive history
- Pivot resolved IPs to their dossiers
- Report phishing to registrar/host