Cannot open support ticket on disabled Azure subscription (fraud incident) — deletion deadline approaching

Anônima
2026-05-16T02:23:06.5466667+00:00

Summary: Production subscription (ID prefix d702dd0c-…, tenant prefix d57189da-…) was disabled on 2026-05-11 after a credential compromise incident. Microsoft applied two system deny assignments — one at the subscription scope (full-deny on all users), and another at the root scope on the compromised user account.

I cannot create a support ticket through any channel:

  • az support in-subscription tickets createReadOnlyDisabledSubscription
  • az support no-subscription tickets createInvalidSupportPlan (Free support plan)
  • Portal "New support request" with Severity C → "We were unable to create a support request for this subscription because it may be disabled. Get help with disabled subscriptions at [http://aka.ms/AzureSubHelp]"

The aka.ms/AzureSubHelp page directs back to opening a support request — which is the action being blocked.

Two prior tickets opened before the subscription was disabled remain unresolved (one without first response, one stalled in customer-reply state).

Fraudulent resource groups created by the attacker remain in the subscription because the system deny assignment blocks all write/delete on subscription scope. Azure already deallocated all attacker compute as a side effect of the disable, so no resources are running — only empty RG records remain.

Subscription is scheduled for permanent deletion on 2026-08-09.

What I need (any of these is helpful):

  1. Routing to a Microsoft engineer with permission to review the case and either reactivate the subscription or confirm the next valid path.
  2. Confirmation of whether reactivation is still possible at this stage and what evidence/identity verification is required.
  3. Clarification on whether the 2026-08-09 deletion is a hard deadline, or if it pauses while a support thread is active.

Full IDs (subscription, tenant, deny assignments, prior ticket numbers) and the original incident remediation log are available privately on request — happy to share with Microsoft staff via direct message or via the support portal if reachable.Summary: Production subscription (ID prefix d702dd0c-…, tenant prefix d57189da-…) was disabled on 2026-05-11 after a credential compromise incident. Microsoft applied two system deny assignments — one at the subscription scope (full-deny on all users), and another at the root scope on the compromised user account.

I cannot create a support ticket through any channel:

  • az support in-subscription tickets createReadOnlyDisabledSubscription
  • az support no-subscription tickets createInvalidSupportPlan (Free support plan)
  • Portal "New support request" with Severity C → "We were unable to create a support request for this subscription because it may be disabled. Get help with disabled subscriptions at [http://aka.ms/AzureSubHelp]"

The aka.ms/AzureSubHelp page directs back to opening a support request — which is the action being blocked.

Two prior tickets opened before the subscription was disabled remain unresolved (one without first response, one stalled in customer-reply state).

Fraudulent resource groups created by the attacker remain in the subscription because the system deny assignment blocks all write/delete on subscription scope. Azure already deallocated all attacker compute as a side effect of the disable, so no resources are running — only empty RG records remain.

Subscription is scheduled for permanent deletion on 2026-08-09.

What I need (any of these is helpful):

  1. Routing to a Microsoft engineer with permission to review the case and either reactivate the subscription or confirm the next valid path.
  2. Confirmation of whether reactivation is still possible at this stage and what evidence/identity verification is required.
  3. Clarification on whether the 2026-08-09 deletion is a hard deadline, or if it pauses while a support thread is active.

Full IDs (subscription, tenant, deny assignments, prior ticket numbers) and the original incident remediation log are available privately on request — happy to share with Microsoft staff via direct message or via the support portal if reachable.

Controle de acesso baseado em função do Azure
Controle de acesso baseado em função do Azure

Um serviço do Azure que fornece gerenciamento de acesso refinado para recursos do Azure, permitindo que você conceda aos usuários somente os direitos de que eles precisam para trabalhar.


2 respostas

Classificar por: Mais Antigo
  1. Dio Xavier 295.5K Pontos de reputação Moderador Voluntário
    2026-05-16T14:50:17.7866667+00:00

    Olá

    Bem vindo à Comunidade Microsoft Azure.

    Bom dia, Bruno. Nossos fóruns tem suporte nativo em Português, sempre que interagir conosco utilize nosso idioma. Em relação ao incidente, vou escalonar para a equipe de suporte avançado pois a anbalise exige dados sigilosos. Aguarda por gentileza a interação por "mensagem privada" de um agente através deste mesmo post.

    Boa sorte e avise-nos sobre o resultado.

    Se a resposta tiver ajudado a resolver o problema, por gentileza marque-a como Resposta Útil. Essa ação encerra a thread, sinaliza a solução correta e ajuda outras pessoas com a mesma dúvida a encontrarem a resposta com mais facilidade. Caso ainda precise de suporte ou tenha novas perguntas, fique à vontade para utilizar este mesmo post.

    Esta resposta foi útil?


  2. Anônima
    2026-06-02T15:45:33.93+00:00

    Já abrimos 3 chamados direto na Azure, sem resposta
    ID dos chamados
    2605130040011289

    2605110040011286

    2605110040009890

    Esta resposta foi útil?

    0 comentários Sem comentários

Sua resposta

As respostas podem ser marcadas como ‘Aceitas’ pelo autor da pergunta e ‘Recomendadas’ pelos moderadores, o que ajuda os usuários a saber a resposta que resolveu o problema do autor.