A Microsoft offering that enables tracking of cloud usage and expenditures for Azure and other cloud providers.
Hello Adolfo Lira
The root cause was an intrusion via a global administrative account with the highest permissions in the tenant, allowing attackers to provision unauthorized resources and manipulate Access Control (IAM) deny assignments. This deliberate and possibly automated attack altered permissions, effectively locking out legitimate administrators from managing the subscription and its resources.
The resolution involved removing all five users from the deny assignments list to restore administrative access. The customer successfully deleted all maliciously created resources within the affected subscription. Microsoft support disabled the three additional subscriptions created by the attackers, but the customer requested assistance to remove the associated unauthorized costs. The customer confirmed regaining access after the deny assignments were removed but still seeks help with billing adjustments related to the incident.
Thanks,
Suchitra.