Earlier quoted context omitted.
> Also looks like they're kids and don't have the hang of security According to the testimony they know enough to almost completely compromise a Azure tenant to the point that a foreign actor almost, ALMOST, could gain access with high privileges with a DOGE created username/password combination without being noticed because all monitoring was disabled. The only thing which prevented that to happen was a luckily stil…
So, what would happen if they used VPNs in USA?
I would have set a security policy which does not allow any kind of inbound admin related traffic from any unknown IP or device at all, including domestic IPs (and VPNs).
But that's just me, I don't know what the preferences of other dev(sec)ops engineers are.