A cloud-based identity and access management service for securing user authentication and resource access
Security Incident Response: Unauthorized Azure Resources Creation and Privileged Account Abuse — Assistance Needed
Problem description
I am experiencing a security incident where an unauthorized user created in Microsoft Entra, assigned privileged roles including Global Administrator, registered MFA methods, and used this access to deploy Azure resources across multiple regions. Despite containing the unauthorized account and reviewing logs, I am unable to delete the deployed resources due to authorization failures. I seek guidance on identifying the exact authorization controls blocking resource deletion and steps to fully recover and decommission the affected subscriptions.
Environment
The affected environment involves Microsoft Entra tenant connected to Azure subscriptions, including a sponsorship subscription and others, with resources created across multiple regions. Specific resource details and SKU information are not provided.
What I've already tried
I have contained the unauthorized Entra user account and reviewed audit and sign-in logs confirming the suspicious activities. I attempted to delete the unauthorized Azure resources, but all deletion efforts failed with 'AuthorizationFailed' errors, despite having Owner and User Access Administrator permissions. I also checked for deny assignments, but the deny assignment blade is inaccessible, and no Locks or deny assignments are confirmed to be in place or removable at this time.
Current status
The incident remains unresolved as the unauthorized resources are still deployed and cannot be deleted due to authorization issues. I am requesting assistance to identify and remove the authorization restrictions blocking cleanup, and to decommission the impacted subscriptions after cleanup.