A cloud-based identity and access management service for securing user authentication and resource access
If your Azure account has been compromised and you are unable to access or receive support, here are some steps you can take to address the situation:
- Change Credentials: Immediately change the credentials for your Azure account, especially for any tenant admins and users with role-based access control (RBAC). Ensure that multi-factor authentication (MFA) is enabled for all accounts to enhance security.
- Review Activity Logs: Check the Microsoft Entra sign-in logs to identify unusual sign-in patterns. This can help you understand the extent of the compromise and identify unauthorized access.
- Identify Compromised Resources: Use the Azure Activity Log to check for any unauthorized activity, such as changes to billing or resource configurations. If you find resources created by unauthorized users, you may need to disable or delete them.
- Contact Support: If you are unable to open a support ticket due to not having a support plan, consider contacting Azure support through other means, such as social media or community forums, to explain your situation. They may provide guidance on how to regain access or escalate your issue.
- Secure Your Environment: After addressing the immediate threats, focus on securing your Azure environment by following best practices for cloud security. This includes regularly reviewing your security posture and ensuring that all accounts have the necessary protections in place.
Since you mentioned that you do not want to reactivate your subscription due to the risk of allowing hackers back in, it is crucial to ensure that you have taken all necessary steps to secure your account before considering reactivation.
References: