Azure subscription compromised – unauthorised VM charges increasing, locked out of tenant and unable to raise Azure Billing support request

Bernard Kelly 0 Reputation points
2026-08-27T12:14:34.68+00:00

I am an individual Azure customer, not a company. I created my Azure subscription and Entra tenant myself using my personal Microsoft account, which uses a Gmail address for sign-in.

My Azure environment appears to have been compromised.

An Azure VM/resources were deployed without my authorisation and substantial Azure consumption has accumulated. I received an Azure notification relating to the VM deployment despite not deploying it myself.

I can still authenticate to my personal Microsoft account and access parts of the Azure portal. I can see my Azure billing relationship and the affected Entra tenant.

However, when I attempt to switch into the affected Entra tenant, Microsoft requires an Authenticator/MFA code for my Gmail identity that I do not possess.

Consequently, I cannot:

  • access or stop the Azure resources;
  • inspect the subscription's IAM role assignments;
  • inspect the affected tenant's users/administrators;
  • use Global Administrator Elevate Access;
  • cancel/suspend the affected subscription; or
  • create an Azure Billing/Subscription Management support request against the affected subscription.

Meanwhile, the Azure consumption continues to increase.

Similar Microsoft Q&A incident

I found another recent Microsoft Q&A question that appears structurally very similar:

Unable to create Azure Billing support request after account compromise and loss of subscription permissions

In that case, Edgar Salas reported that after his Microsoft account was compromised:

  • unauthorised Azure resources generated substantial charges;
  • his billing relationship with the subscription remained;
  • his Azure subscription permissions had disappeared;
  • he could not create an Azure Billing support request because he no longer had permission to the subscription.

Edgar subsequently discovered an unknown external guest account which had been granted Global Administrator and Subscription Owner, while his own Azure role assignments had been removed.

Because Edgar still had sufficient Global Administrator access, he was able to use:

Microsoft Entra ID → Properties → Access management for Azure resources (Elevate Access)

to regain sufficient Azure RBAC access and recover control of the subscription.

I cannot perform Edgar's recovery procedure because I cannot enter the affected Entra tenant at all. Switching to it results in the MFA/Authenticator challenge described above.

I am not claiming that the same RBAC/Global Administrator changes occurred in my tenant because I cannot access the tenant to verify that. However, I believe Microsoft needs to investigate whether similar changes occurred.

Microsoft support problem

I reported the compromise to Microsoft while the unauthorised Azure consumption was still occurring.

Microsoft support case 2608230040000994 was opened.

Unfortunately, the case was routed to the Microsoft 365 Data Protection Team as a Global Administrator recovery request.

They requested:

  • company incorporation/business registration documentation;
  • written authorisation from a company trustee;
  • identification for the trustee.

No such company or trustee exists.

This is an Azure/Entra tenant I created as an individual.

I explained this and explicitly offered to provide:

  • government-issued photo ID;
  • Azure billing/account information;
  • payment-method/account ownership evidence; and
  • any other identity verification appropriate to an individually owned Azure tenant.

I asked Microsoft to provide the appropriate verification procedure for an individually owned tenant.

I also repeatedly requested that Microsoft suspend the affected Azure subscription/resources immediately, because I do not need the resources preserved and the unauthorised consumption is continuing.

The support team has now said that verification cannot be completed and intends to close the service request, stating that I “refused to continue with the verification process.”

I did not refuse identity verification. I cannot provide corporate documentation for a company that does not exist.

What I need help with

How can an individual Azure customer reach Azure Billing/Subscription Management or the appropriate Azure security team when the compromise itself has removed/prevented the access required to create an Azure support request?

Specifically:

  1. Is there an escalation route for Azure Billing/Subscription Management that does not require access to the compromised subscription?
  2. Can Microsoft suspend the affected subscription while identity recovery/investigation continues?
  3. What is the appropriate Microsoft recovery procedure for an individually owned Entra tenant where there is no company or trustee?
  4. How can I formally dispute the Azure consumption generated by the unauthorised resources?
  5. Can Microsoft investigate the Azure Activity Log, Entra sign-in/audit logs, RBAC changes, Global Administrator changes and authentication-method changes to establish what occurred?

I am trying to find the correct Microsoft escalation route to:

stop the continuing unauthorised Azure consumption, investigate the compromise, and dispute the resulting charges.

Any guidance from Microsoft staff/moderators on how this can be escalated to the appropriate Azure team would be greatly appreciated.

Azure Cloud Services
Azure Cloud Services

An Azure platform as a service offer that is used to deploy web and cloud applications.

0 comments No comments

2 answers

Sort by: Newest
  1. Bernard Kelly 0 Reputation points
    2026-08-28T11:59:30.6033333+00:00

    Hi Zoha,

    Thank you for the response.

    Unfortunately, the telephone support route you describe is the route I have already been attempting to use.

    I have spoken to multiple Microsoft support representatives and repeatedly explained that this is ongoing unauthorised Azure consumption and that I cannot access the affected subscription to stop it.

    The resulting case, 2608230040000994, was routed to the Microsoft 365 Data Protection Team and handled as a corporate Global Administrator recovery request.

    I was asked for company incorporation and trustee documentation. I explained in writing that there is no company or trustee and that this is an individually owned Azure/Entra environment. I explicitly offered government-issued photo ID, billing/payment evidence and any appropriate individual ownership verification.

    The case was subsequently marked for closure on the basis that I had “refused to continue with the verification process”, despite me never refusing verification. ???

    Microsoft called me again today after I challenged this. I again confirmed that I am willing to provide my driving licence immediately and requested a formal complaint regarding the handling of the case.

    I attempted to upload my driving licence through Microsoft's Secure File Exchange immediately afterwards, but the existing workspace returned “file upload failed”. The senior support representative had indicated that the existing upload workspace might have been disabled and that Microsoft may need to create a new one. I have notified Microsoft in writing and requested a new secure upload link.

    I have also explicitly requested suspension of the affected Azure subscription/resources while the identity investigation continues.

    Is there a specific Azure Billing / Subscription Management or account-compromise escalation route that the telephone support representative should use internally?

    My difficulty is no longer identifying what Microsoft needs to do. It is getting the incident transferred from the Microsoft 365 Global Administrator recovery process to the Azure team capable of containing the subscription and investigating the unauthorised consumption.

    Thanks, Bernard

    Was this answer helpful?

    0 comments No comments

  2. Zoha Fatima 510 Reputation points
    2026-08-27T14:08:58.9266667+00:00

    Hi Bernard,

    I am sorry you are dealing with continuing charges while locked out. This forum cannot suspend the subscription or inspect Microsoft’s internal logs.

    Because the portal is inaccessible, Microsoft’s official guidance is to call the Azure customer-service number for your country. State clearly: “Ongoing Azure account takeover with active unauthorised consumption.” Request:

    • Immediate subscription suspension or spending containment.
    • Transfer of case 2608230040000994 to Azure Billing and Subscription Management/account-compromise specialists.
    • Individual ownership verification, since this is not a corporate tenant.
    • Preservation and review of Entra sign-in/audit logs, authentication changes, Azure Activity Log and RBAC changes.

    Azure billing support is free for every customer. Submit a written billing dispute containing the first unauthorised activity date, VM/resource details, invoices, deployment notification and proof of payment-account ownership. Refunds require Microsoft’s investigation and are not automatic.

    Meanwhile, secure both your Gmail and Microsoft accounts: change passwords from a clean device, revoke active sessions, review recovery methods and enable new MFA. Inform your card issuer, but do not rely on replacing the card to stop Azure resources or close the billing relationship.

    Thank you, and feel free to respond back for more assistance.

    Was this answer helpful?


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.