Azure Subscription Blocked by UnusualActivity – Escalation Request

Adolfo Lira 0 Reputation points
2026-05-23T04:47:20.8966667+00:00

My Azure account was compromised by unauthorized access. Within a few hours, Microsoft identified the activity and disabled my subscriptions as a protective measure. I successfully recovered access to the account with no critical impact on data.

However, there is an active [UnusualActivity] block applied by Microsoft on my subscription, preventing any access. This type of restriction cannot be removed manually — it requires direct intervention from Microsoft support to be lifted.

I have opened multiple tickets through the Azure portal more than 3 days ago, all classified as Severity A, and have not received any response so far. This behavior appears to be a known pattern in UnusualActivity block cases: tickets remain open without being addressed, regardless of the severity level assigned.

I need guidance on the correct channel to escalate this case and obtain an urgent resolution, as the subscription's unavailability is directly impacting my operations.

Cost Management
Cost Management

A Microsoft offering that enables tracking of cloud usage and expenditures for Azure and other cloud providers.


2 answers

Sort by: Oldest
  1. AI answer

    2026-05-23T04:47:44.3+00:00

    For an Azure subscription blocked due to unusual or potentially fraudulent activity, only Microsoft support can remove the block. The appropriate escalation path is:

    1. Open or reuse an Azure support request
      • Use the Azure portal to create a billing/support request for the affected subscription, categorized under subscription or billing issues.
      • Clearly state that the subscription is blocked due to security/unusual activity and that access is required to be restored.
      • If the subscription was acquired via a partner (CSP), the partner must open and own the support request on behalf of the customer.
    2. Avoid duplicate requests
      • Do not submit multiple assistance requests for the same incident while an existing case is in process. Submitting multiple tickets can slow down handling and complicate escalation.
    3. If the subscription is blocked due to inactivity
      • For unused or inactive subscriptions that have been blocked, the documented path is to contact Microsoft Support (or the managing partner) to unblock the subscription.
      • If the subscription remains blocked and no action is taken, it can be deleted after the notification period, which results in data loss and requires creating a new subscription.
    4. If the subscription was deleted or the offer retired
      • If the subscription has already been deleted due to inactivity or is based on a retired offer (for example, Access to Active Azure Directory subscription MS-AZR-0110P), it cannot be reactivated and a new subscription must be created.
    5. Continue working with support for security-related blocks
      • For compromised subscriptions, Microsoft guidance is to immediately secure identities (change credentials, enforce MFA, review risky users and sign-in logs) and then work with Azure support to remediate and clean up compromised resources.
      • Ensure that all requested information from support (tenant details, subscription IDs, incident description, timelines) is provided promptly so the case can be progressed and the block reviewed.

    If the subscription is managed under a partner program, escalation must go through the partner’s support channel, which in turn escalates to Microsoft via Partner Center.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

  2. Suchitra Suregaunkar 16,780 Reputation points Microsoft External Staff Moderator
    2026-06-04T17:53:34.9766667+00:00

    Hello Adolfo Lira

    The root cause was an intrusion via a global administrative account with the highest permissions in the tenant, allowing attackers to provision unauthorized resources and manipulate Access Control (IAM) deny assignments. This deliberate and possibly automated attack altered permissions, effectively locking out legitimate administrators from managing the subscription and its resources.

    The resolution involved removing all five users from the deny assignments list to restore administrative access. The customer successfully deleted all maliciously created resources within the affected subscription. Microsoft support disabled the three additional subscriptions created by the attackers, but the customer requested assistance to remove the associated unauthorized costs. The customer confirmed regaining access after the deny assignments were removed but still seeks help with billing adjustments related to the incident.

    Thanks,

    Suchitra.

    Was this answer helpful?


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.