I am an individual Azure customer, not a company. I created my Azure subscription and Entra tenant myself using my personal Microsoft account, which uses a Gmail address for sign-in.
My Azure environment appears to have been compromised.
An Azure VM/resources were deployed without my authorisation and substantial Azure consumption has accumulated. I received an Azure notification relating to the VM deployment despite not deploying it myself.
I can still authenticate to my personal Microsoft account and access parts of the Azure portal. I can see my Azure billing relationship and the affected Entra tenant.
However, when I attempt to switch into the affected Entra tenant, Microsoft requires an Authenticator/MFA code for my Gmail identity that I do not possess.
Consequently, I cannot:
- access or stop the Azure resources;
- inspect the subscription's IAM role assignments;
- inspect the affected tenant's users/administrators;
- use Global Administrator Elevate Access;
- cancel/suspend the affected subscription; or
- create an Azure Billing/Subscription Management support request against the affected subscription.
Meanwhile, the Azure consumption continues to increase.
Similar Microsoft Q&A incident
I found another recent Microsoft Q&A question that appears structurally very similar:
Unable to create Azure Billing support request after account compromise and loss of subscription permissions
In that case, Edgar Salas reported that after his Microsoft account was compromised:
- unauthorised Azure resources generated substantial charges;
- his billing relationship with the subscription remained;
- his Azure subscription permissions had disappeared;
- he could not create an Azure Billing support request because he no longer had permission to the subscription.
Edgar subsequently discovered an unknown external guest account which had been granted Global Administrator and Subscription Owner, while his own Azure role assignments had been removed.
Because Edgar still had sufficient Global Administrator access, he was able to use:
Microsoft Entra ID → Properties → Access management for Azure resources (Elevate Access)
to regain sufficient Azure RBAC access and recover control of the subscription.
I cannot perform Edgar's recovery procedure because I cannot enter the affected Entra tenant at all. Switching to it results in the MFA/Authenticator challenge described above.
I am not claiming that the same RBAC/Global Administrator changes occurred in my tenant because I cannot access the tenant to verify that. However, I believe Microsoft needs to investigate whether similar changes occurred.
Microsoft support problem
I reported the compromise to Microsoft while the unauthorised Azure consumption was still occurring.
Microsoft support case 2608230040000994 was opened.
Unfortunately, the case was routed to the Microsoft 365 Data Protection Team as a Global Administrator recovery request.
They requested:
- company incorporation/business registration documentation;
- written authorisation from a company trustee;
- identification for the trustee.
No such company or trustee exists.
This is an Azure/Entra tenant I created as an individual.
I explained this and explicitly offered to provide:
- government-issued photo ID;
- Azure billing/account information;
- payment-method/account ownership evidence; and
- any other identity verification appropriate to an individually owned Azure tenant.
I asked Microsoft to provide the appropriate verification procedure for an individually owned tenant.
I also repeatedly requested that Microsoft suspend the affected Azure subscription/resources immediately, because I do not need the resources preserved and the unauthorised consumption is continuing.
The support team has now said that verification cannot be completed and intends to close the service request, stating that I “refused to continue with the verification process.”
I did not refuse identity verification. I cannot provide corporate documentation for a company that does not exist.
What I need help with
How can an individual Azure customer reach Azure Billing/Subscription Management or the appropriate Azure security team when the compromise itself has removed/prevented the access required to create an Azure support request?
Specifically:
- Is there an escalation route for Azure Billing/Subscription Management that does not require access to the compromised subscription?
- Can Microsoft suspend the affected subscription while identity recovery/investigation continues?
- What is the appropriate Microsoft recovery procedure for an individually owned Entra tenant where there is no company or trustee?
- How can I formally dispute the Azure consumption generated by the unauthorised resources?
- Can Microsoft investigate the Azure Activity Log, Entra sign-in/audit logs, RBAC changes, Global Administrator changes and authentication-method changes to establish what occurred?
I am trying to find the correct Microsoft escalation route to:
stop the continuing unauthorised Azure consumption, investigate the compromise, and dispute the resulting charges.
Any guidance from Microsoft staff/moderators on how this can be escalated to the appropriate Azure team would be greatly appreciated.