Additional Microsoft Entra services and features related to identity, access, and network security
Take these actions immediately:
- Secure the account before changing anything else.
- Run a full malware/antivirus scan on the PC first.
- On Windows 8.1 or Windows 10/11, open Start, search for Windows Defender, and follow the on-screen instructions.
- Important: do the full scan before changing the password.
- Recover and secure the Microsoft account.
- Use the Microsoft Sign-in Helper for hacked account support: Start
- If sign-in still works after the scan, change the password immediately.
- If sign-in does not work, reset the password.
- Check for account changes made by the attacker.
- Review account settings such as connected accounts, forwarding, and automatic replies.
- If Azure resources or access were compromised, contain the Azure side.
- Immediately change credentials for tenant admins and anyone with RBAC access on Azure subscriptions.
- Ensure MFA is registered and enforced for tenant admins and RBAC owners.
- Review admin password recovery email addresses and phone numbers in Microsoft Entra ID and update them if needed.
- Review risky users and risk reports in Microsoft Entra ID / Identity Protection.
- Review Microsoft Entra sign-in logs for unusual sign-in patterns around the time access changed.
- Check the Azure Activity Log for unauthorized changes to billing, usage, or configuration.
- Review spending anomalies in Azure Cost Management.
- Remove compromised Azure resources.
- Disable or delete resources created by the unauthorized party.
- After the threat actor is removed, clean the compromised resources and continue monitoring logs and audit trails.
- If a subscription was deleted or resources disappeared, use support where self-service is not available.
- For deleted storage accounts, recovery can be attempted from the Azure portal using Restore, or by creating a support request under Help + support.
- In Create a support request for storage account recovery, use:
- Issue type: Technical
- Service: Storage Account Management
- Problem type: Deletion and Recovery
- Problem subtype: Recover deleted storage account
- If the goal is to remove unused or unnecessary Azure assets after regaining control:
- Delete unnecessary or unused subscriptions.
- Transfer subscriptions to an active tenant if needed.
- Warning: deleting a Microsoft Entra tenant deletes all resources within that tenant. This is destructive and should only be done after confirming ownership and that required data is no longer needed.
For the specific request to destroy the account or migrated data: the supported path is to first secure the account, then delete unnecessary subscriptions or delete the tenant only after recovery and verification. If data was moved or deleted by an attacker, review logs first so legitimate resources are not destroyed accidentally.
- Hello , welcome to Account help & learning
- How to recover a hacked or compromised Microsoft account
- How to recover a hacked or compromised Microsoft account
- Detect and respond to security alerts
- Protect tenants and subscriptions from abuse and fraud attacks
- Best practices for Azure Storage data protection, backup, and recovery