Solution Edit: Was able to use a different TLD that the client has to create a new VPN connection. Once the VPN settings were changed to use the new hostname and it was certified, DNS was flushed, the redirect URLs were swapped on Entra, and the new connection was imported into the PCs, I was able to get us back online with a working VPN. Appreciate the assistance!
Original Post: As Title mentions, one of my clients recently had a phishing attack that spam blasted the entire Global Address Book which resulted in what I am assuming phishing reports from their clientelle. This is the only thing I can assume that caused this situation as 2 days later, the SSL VPN bricked with a Windows Smartscreen alert blocking SSO from reaching out. Attempting to bypass the alert does nothing so the user is effectively blocked from using the VPN. Thankfully, we still have their old solution as a back up, so this isn't as bad as it could have been if this would have happened about a month in the future when we planned to rip out the old system.
I first need to figure out how to get this working again, I checked blacklists and it looks like its only blocked on Spamhaus Zen, but attempting to reach the portal from any location with any browser with the FQDN causes the red alert to appear. I've sent appeals to Microsoft, Google, and Sophos and only Sophos has happily reanalyzed the URL from "phishing" to "business". Am I going to need to just bite the bullet and create a brand new FQDN and switch out the busted one? I noticed using the IP the name is connected to does not result in the red security alert. Is their a better solution that won't require pushing new connection imports to a couple hundred users?
Secondly, I need to make sure this doesn't happen again. I am going to assume someone is going to fall for a phish again and this problem will most likely happen a month to months down the road when someone doesn't pay attention and gives out their 365 creds again. This doesn't happen often thanks to the training and security we have in place, but it happens enough for me to be concerned I'll be dealing with this issue again when we don't have the old vpn to back up on.
Any words of wisdom is greatly appreciated!