Summary: Production subscription (ID prefix d702dd0c-…, tenant prefix d57189da-…) was disabled on 2026-05-11 after a credential compromise incident. Microsoft applied two system deny assignments — one at the subscription scope (full-deny on all users), and another at the root scope on the compromised user account.
I cannot create a support ticket through any channel:
-
az support in-subscription tickets create → ReadOnlyDisabledSubscription
-
az support no-subscription tickets create → InvalidSupportPlan (Free support plan)
- Portal "New support request" with Severity C → "We were unable to create a support request for this subscription because it may be disabled. Get help with disabled subscriptions at [http://aka.ms/AzureSubHelp]"
The aka.ms/AzureSubHelp page directs back to opening a support request — which is the action being blocked.
Two prior tickets opened before the subscription was disabled remain unresolved (one without first response, one stalled in customer-reply state).
Fraudulent resource groups created by the attacker remain in the subscription because the system deny assignment blocks all write/delete on subscription scope. Azure already deallocated all attacker compute as a side effect of the disable, so no resources are running — only empty RG records remain.
Subscription is scheduled for permanent deletion on 2026-08-09.
What I need (any of these is helpful):
- Routing to a Microsoft engineer with permission to review the case and either reactivate the subscription or confirm the next valid path.
- Confirmation of whether reactivation is still possible at this stage and what evidence/identity verification is required.
- Clarification on whether the 2026-08-09 deletion is a hard deadline, or if it pauses while a support thread is active.
Full IDs (subscription, tenant, deny assignments, prior ticket numbers) and the original incident remediation log are available privately on request — happy to share with Microsoft staff via direct message or via the support portal if reachable.Summary: Production subscription (ID prefix d702dd0c-…, tenant prefix d57189da-…) was disabled on 2026-05-11 after a credential compromise incident. Microsoft applied two system deny assignments — one at the subscription scope (full-deny on all users), and another at the root scope on the compromised user account.
I cannot create a support ticket through any channel:
-
az support in-subscription tickets create → ReadOnlyDisabledSubscription
-
az support no-subscription tickets create → InvalidSupportPlan (Free support plan)
- Portal "New support request" with Severity C → "We were unable to create a support request for this subscription because it may be disabled. Get help with disabled subscriptions at [http://aka.ms/AzureSubHelp]"
The aka.ms/AzureSubHelp page directs back to opening a support request — which is the action being blocked.
Two prior tickets opened before the subscription was disabled remain unresolved (one without first response, one stalled in customer-reply state).
Fraudulent resource groups created by the attacker remain in the subscription because the system deny assignment blocks all write/delete on subscription scope. Azure already deallocated all attacker compute as a side effect of the disable, so no resources are running — only empty RG records remain.
Subscription is scheduled for permanent deletion on 2026-08-09.
What I need (any of these is helpful):
- Routing to a Microsoft engineer with permission to review the case and either reactivate the subscription or confirm the next valid path.
- Confirmation of whether reactivation is still possible at this stage and what evidence/identity verification is required.
- Clarification on whether the 2026-08-09 deletion is a hard deadline, or if it pauses while a support thread is active.
Full IDs (subscription, tenant, deny assignments, prior ticket numbers) and the original incident remediation log are available privately on request — happy to share with Microsoft staff via direct message or via the support portal if reachable.