Tag not monitored by Microsoft.
Immediately take the following actions:
- Stop further charges by deleting the lab and its resources
If this is an Azure DevTest Lab or Azure Lab Services lab in a resource group you control:- In the Azure portal, go to the lab resource.
- On the lab Overview page, select Delete from the top menu.
- On the confirmation page, enter the lab name and select Delete.
- Monitor progress in Notifications; deletion can take some time.
- After the lab is deleted, if the resource group was created only for this lab, delete the resource group as well:
- Go to Resource groups in your subscription.
- Select the resource group that contained the lab.
- Select Delete resource group, confirm the name, and select Delete.
Deleting the lab and then the resource group removes all lab-related resources and stops ongoing usage charges.
- Ensure unauthorized resources are removed and prevented in future
- Regularly reconcile your Azure inventory and delete any unauthorized resources from the subscription.
- Use tags, management groups, and separate subscriptions to organize and track assets so unauthorized labs are easier to spot and remove.
- Use Azure Policy to restrict which resource types can be created (for example, only approved lab types) and Azure Resource Graph to discover any unapproved resources.
- Investigate unexpected charges and who created the lab
- Review the invoice and usage for the subscription in Cost analysis to confirm that the charges are coming from this lab resource group.
- Analyze audit logs and user permissions at the subscription/resource group scope to identify who created the lab and how it was authorized.
- If needed, create an Azure billing support request (billing support is free) so a billing engineer can help investigate and explain the charges.
- Engage billing support for charge review or adjustment
- Create a billing support request from the Azure portal (Help + Support → New support request, or via the support request creation link) and choose a billing-related problem type.
- Clearly state that an unauthorized lab resource group was created, list the subscription ID, resource group name, dates, and the approximate amount (21,000).
- Upload any screenshots of Cost analysis and invoices showing the charges.
- Billing support typically responds within one business day and can advise on possible credits or adjustments.
- Strengthen governance to avoid recurrence
- Define and maintain an inventory of approved Azure resources and lab types.
- Use Azure Policy to monitor and block unapproved resources.
- Ensure only appropriate users have role-based access to create labs and resource groups.
These steps will stop ongoing charges by deleting the lab resources, help you understand and potentially dispute the existing charges, and reduce the risk of unauthorized labs in the future.
References:
- Azure Lab Services - Administrator guide
- Quickstart: Create a lab in the Azure portal
- Tutorial: Create a lab and VM and add a user in DevTest Labs
- Security Control: Inventory and Asset Management
- Understand the terms in your Azure usage and charges file
- Request for Refund – Accidental Charges in Pay-As-You-Go Subscription - Microsoft Q&A
- I need help with bill waiver on my subscription but cannot open a support ticket. - Microsoft Q&A