r/MSFTAzureSupport • • 24d ago

Technical Question Azure account compromised: $550k charged for unauthorized Claude usage from azure marketplace. What should I do?

4 Upvotes

My Azure startup account had about $10k in promotional credits. While I was in the hospital, I received unexpected OTP emails(but I igroned them). I later found roughly $550,000 (₹5 crore) in Azure charges, apparently from unauthorized Claude AI usage through Azure Marketplace over about 9–13 days. There was claude usage from azure marketplace. I had a debit card attached on my azure account. I am just a college student, I think I had a minor heart attack yesterday.

I didn’t create these workloads or authorize the usage. I’ve disabled resources and contacted Azure Support, but I’m worried about being held responsible for an amount I cannot pay. The Azure support person said there is no fradulant activity detected in the account.

  1. Has anyone dealt with unauthorized Azure charges this large?
  2. Did Microsoft waive the bill after investigating? 3, Do they do court procedings with such cases?
  3. Which fraud, billing, or security team should I contact, and what evidence should I preserve?

r/MSFTAzureSupport • • 5d ago

Technical Question Can't sign in using Outlook

1 Upvotes

I'm trying to sign-in to my Azure profile for school. I'm not receiving the notification within Outlook to get in. My other options to get in use my old phone number that I no longer have access to because my phone broke. I've contacted my school's lab support and they can't help me. Microsoft's automated support won't help because I have a student account. What are my options here?

r/MSFTAzureSupport • • Aug 24 '26

Technical Question Locked out of my tenant

4 Upvotes

Solved!

TLDR: create a new microsoft account that can raise a service request to fix the other account.

It turned out that the only thing I could do was contact Microsoft Support to reset the 2FA for that account. To make it a bit more weird it was that the problematic account was really an old hotmail.com account. 🙄

Here's what I did, and there are probably easier ways to do this, but my first approach was to try to initiate an internal admin takeover or an external admin takeover:

  1. Logged in with that account at account.microsoft.com, removed all the other email addresses associated with it. Logged out.
  2. Signed up my domaiin for a free trial of O365, that gave me an <name>@<domain>.onmicrosoft.com account.
  3. Logged into azure with the onmicrosoft.com account, added my domain as a custom domain, used the details to verify that I own and control the domain (created a TXT record) and tried to initiate a tenant takeover.
  4. This failed with no helpful message onscreen, but using browser devtools I saw it wouldn't let me because there was still an active tenant for domain.
  5. Through the O365 admin portal I tried to claim the domain and that failed for the same reason, but with a more helpful error message.
  6. Using that account I raised a service request to get help with the domain take over.
  7. That got rerouted to get someone who could reset my 2FA for the old account
  8. That took a few days. They had me verify I owned that email address, but then it was done, I had to re-setup 2FA and I could get access to that tenant again.
  9. Problem solved.

I'm now doing the clean up, importantly cancelling the O365 account, and switching everything to real accounts on my domain, also having a couple of backup admins, in case I get locked out again.

Detail of problem follows.

I'm trying to get into my personal tenant directory in Azure, but I can only get half way logged in.

I think it's trying to authenticate me with my personal domain, but that doesn't work

Here's what happens:

  1. I go to portal.azure.com and log in with my personal microsoft account, auth via the Authenticator app
  2. Sometimes I get prompted to re-authenticate but I don't get a notification from the authenticator app, I try another way and get prompted to enter a 6 digit code, I can't generate one in the app
  3. If I don't get prompted to re-authenticate, or cancel out of it, I end up on the portal home page. However instead of my default tenant under my user name (top right of screen) I have this f8cdef31-a31e-4b4a-93e4-5f571e91255aas my Directory and Domain
  4. If I try to switch to the tenant associated with my own domain (my default) I get stuck in step 2.
  5. If I go to to the Entra ID blade I get a series of messages saying "Interaction required" and suggesting I re-login, which doesn't help because then I get stuck in step 2 again
  6. After clicking "Ignore" a bunch of times I get details for f8cdef31-a31e-4b4a-93e4-5f571e91255a including that its license is "Microsoft Entra ID Free"
  7. From there I can click on "Manage Tenants" (more "Interaction required") messages, and 3 tenants, the one for my domain, one for my employer, and one for a place I used to work about 10 years ago.
  8. If I try to switch to my personal one I get stuck in step 2 again. I can switch to my employer's one, but my personal account doesn't have a subscription there.

When I get asked to re-authenticate I get it has the email address of my personal Microsoft account (myname@mydomain). There are some flows where I get prompted to enter my email address, if I enter it there I get an error saying it's not valid, or I get this:

ADSTS50020: User account 'myname@mydomain' from identity provider 'live.com' does not exist in tenant 'Microsoft Services' and cannot access the application '74658136-14ec-4630-ad9b-26e160ff0fc6'(ADIbizaUX) in that tenant. The account needs to be added as an external user in the tenant first. Sign out and sign in again with a different Azure Active Directory user account.

If I try to raise a support request I get stuck in step 2. If I try to buy support, I get stuck in step 2.

I think the problem is that myname@mydomain is both a Microsoft personal account (also tied to hotmail and gmail accounts) and an account for my personal domain's tenant. When it tries to authenticate for the one on my tenant I no longer have access to the 2FA method. I get prompted to contact my admin, I'm the only admin.

After many hours chatting with the AI assistant, it seems I need to raise a request to recover the account, but I can't do that without logging in.

On the plus side: I own and manage the domain. I can add MX (etc) records to verify that.

Where do I go from here?

r/MSFTAzureSupport • • 13d ago

Technical Question Central root ca in azure

2 Upvotes

Has anyone implemented a centralised PKI where the Root CA is stored in Azure Key Vault and workloads can automatically obtain the Root CA when they are deployed, as well as receive updated versions when the Root CA needs to be rotated or renewed? I’m looking to implement a centralised PKI for an Azure hub-and-spoke architecture, where workloads across the spokes can automatically obtain and trust the Root CA.

The workloads could include VMs, AKS, containers, App Services and Azure Functions. I’m aware that Azure Machine Configuration can be used to deploy certificates to VMs, but this is specific to VMs. What is the recommended approach for distributing the Root CA to the other Azure workload types using a consistent and automated mechanism? Ideally, I’d like the solution to be fully automated, so that new workloads receive the current Root CA during deployment and existing workloads automatically receive updated versions whenever the Root CA is rotated or renewed.

I will be deploying the root ca in a key vault via terraform a project for the root ca only to update whenever is needed and then each resources to be able to get the latest root ca.

Has anyone implemented something similar, or could you provide guidance on the recommended architecture and distribution mechanism?

r/MSFTAzureSupport • • Aug 13 '26

Technical Question Universal Print Pull-Print Queue Randomly Dies

1 Upvotes

Hey all,

I have a higher ed customer who utilizes Universal Print and they've run into an issue where their pull-print queue randomly dies after 6-8 months of usage. It can be recreated and it will work again, but the fear is that it requires all the remapping on devices.

The root issue is that all jobs fail to send/queue IMMEDIATELY on all devices whether newly imaged or currently in use. There are no logs on any devices apart from an error in event viewer which says the print queue cannot be contacted. However, that print queue exists and responds to Graph queries AND has all the same properties of another queue that IS working.

Has anyone seen this AND does anyone know if there's an option for Microsoft Support where my customer can pay for a single, premium support case and not the whole plan?

Thank you in advance!

r/MSFTAzureSupport • • Jul 29 '26

Technical Question Cannot delete account

1 Upvotes

Hello,

I was trying to delete my Microsoft account but when I do so I get the error that my account is still connected to an organisation. I had a chat with Microsoft support team and they told me that my account is linked to Azure.

When I try to login in Azure I get this error:

The tenant 'Directory predefinita (XXXX-XXXX-XXXX-XXXX-XXXX)' has been deauthenticated and is no longer available. Try signing into another tenant from the dropdown below. Error message: interaction_required: AADSTS5000225: This tenant has been blocked due to inactivity. To learn more about tenant lifecycle policies, see https://aka.ms/TenantLifecycle

How can I have my account unliked to Azure? I don't know at all why I have it.

r/MSFTAzureSupport • • Jun 09 '26

Technical Question Azure Portal login stuck at "Let's keep your account secure" screen

6 Upvotes

hi

Azure Portal works on a PC that was already signed in, but I am experiencing issues when trying to access Azure Portal from a new PC.

Issue:

・i can successfully sign in at `https://login.microsoftonline.com/\`

・When I go to Azure Portal, I get the screen: **"Let's keep your account secure"

・The page only shows a **"Next"** button

・After clicking **"Next"**, it stays on **"Processing..."** indefinitely and never proceeds

What I've checked:

・Chrome and Edge both have the same issue

・InPrivate / Incognito mode has the same issue

・Developer Tools → Console shows no errors

・Developer Tools → Network shows requests returning HTTP 200

・The Issues tab only shows warnings related to viewport and security headers, nothing that looks related to the login failure

Can anyone please advise me what to do?

r/MSFTAzureSupport • • May 07 '26

Technical Question Azure Web App hosting HTML with Google Maps API

2 Upvotes

I have a very simple HTML file that includes a Google Map and I have a Google map key. It looks like this:
<script src="https://maps.googleapis.com/maps/api/js?key=MyKeyHere&libraries=marker&loading=async&callback=initMap" defer></script>

The HTML happens to also include the Aeris Weather component.

When it loads I get the following CORs error:
Cross-Origin Request Blocked: The Same Origin Policy disallows reading the remote resource at https://maps.googleapis.com/maps/api/mapsjs/gen_204?csp_test=true. (Reason: CORS request did not succeed). Status code: (null).

I am serving the page from Azure Static Web Apps. I have a "staticwebapp.config.json" file in my root directory which it is reading, because I have gotten errors.

Google and AI says I need to add the following to the JSON, but it gives me many more errors when I do this:

{
  "globalHeaders": {
    "content-security-policy": "default-src 'self'; script-src 'self' https://maps.googleapis.com; img-src 'self' https://gstatic.com https://*.googleapis.com data:; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; font-src 'self' https://gstatic.com; frame-src https://www.google.com;"
  },
  "navigationFallback": {
    "rewrite": "index.html",
    "exclude": ["/images/*.{png,jpg,gif}", "/css/*"]
  }
}

Any suggestions on how I get get the CSP correct?

r/MSFTAzureSupport • • Mar 05 '26

Technical Question force an Azure VM to use a different route than the default route of the subnet

0 Upvotes

we have servers in Azure and they all go to the internet via DIA.

we have expressroute thru our MPLS to our datacenter and we have a firewall in the DC.

I would like to force 1 VM in Azure to go via the expressroute and firewall for internet rather than going via DIA.

**I dont want to change the way the rest of the servers connect to the internet (atm) **

i am thinking of:

- creating a new route table
- create a new route
- associate the new route/route-table to the VM's NIC

will this command below achieve what i'm hoping to do:

az network nic update --name <NIC-ID> --resource-group <ResourceGroupID> --set ipConfigurations[0].routeTable.id="/subscriptions/<subscriptionID>/resourceGroups/<ResourceGroupID>/providers/Microsoft.Network/routeTables/<NewRoute-Table>"

TIA

r/MSFTAzureSupport • • Apr 04 '26

Technical Question Deployment Failed

2 Upvotes

Hello all,

I am little confused with the quotas staff with Azure. I tried to deploy an Azure AVD with 1 vm to spin for testing but the deployment keeps failing due to Quota exceeded. I checked under my subscription >>Quotas and found that I only used 20%. So why is it failing if I only used 2 of 10. Please explain

r/MSFTAzureSupport • • Apr 01 '26

Technical Question GSA Private Network stopped tunneling certain ports after a Linux server update.

Thumbnail
1 Upvotes

r/MSFTAzureSupport • • Feb 11 '26

Technical Question Ensuring guest OS NIC IP matches Azure Logical Network IP after Hyper-V VM migration to Azure Local

5 Upvotes

I am migrating on-prem Hyper-V VMs into Azure Local (Azure Stack HCI) using Azure Migrate.

Environment:

  • Azure Local logical networks configured as static

Mix of guest OS configurations: DHCP and static

VMs become Arc-enabled after migration

Networking assigned through Azure logical network/NIC

Issue: After migration completes and the VM is running in Azure Local, I am seeing consistent IP mismatches between Azure and the guest OS.

Example:

Azure portal / logical network shows assigned IP: xxx.xxx.xxx.10

Inside VM (ipconfig): shows a different IP (old static or DHCP)

In some cases hidden NICs from pre-migration remain and hold the old configuration

This creates:

IP mismatch between Azure NIC and guest OS

Connectivity issues

Manual cleanup required inside each VM

Question: What is the recommended way to ensure the guest OS NIC configuration aligns with the Azure Local logical network assignment post-migration?

Specifically:

Should Azure Local automatically push the static IP to the guest via Arc/synthetic NIC?

Is manual guest OS IP correction expected after each migration?

Are there best practices to avoid hidden/orphaned NICs and stale IP configs?

Is there a supported workflow/runbook Microsoft recommends for post-migration network alignment?

Goal: I am trying to determine whether IP reconciliation inside the VM is an expected step for every migration, or if there is a configuration approach that ensures the Azure-assigned logical network IP and guest OS IP remain synchronized automatically.I am migrating on-prem Hyper-V VMs into Azure Local (Azure Stack HCI) using Azure Migrate.

Environment:

Azure Local logical networks configured as static

Mix of guest OS configurations: DHCP and static

VMs become Arc-enabled after migration

Networking assigned through Azure logical network/NIC

Issue:
After migration completes and the VM is running in Azure Local, I am seeing consistent IP mismatches between Azure and the guest OS.

Example:

Azure portal / logical network shows assigned IP: xxx.xxx.xxx.10

  • Inside VM (ipconfig): shows a different IP
  • In some cases, hidden NICs from pre-migration remain and hold the old configuration

This creates:

IP mismatch between Azure NIC and guest OS

Connectivity issues

Manual cleanup required inside each VM

Question:
What is the recommended way to ensure the guest OS NIC configuration aligns with the Azure Local logical network assignment post-migration?

Goal:
I am trying to determine whether IP reconciliation inside the VM is an expected step for every migration, or if there is a configuration approach that ensures the Azure-assigned logical network IP and guest OS IP remain synchronized automatically.

r/MSFTAzureSupport • • Jan 29 '26

Technical Question Azure Automation Extension on Arc-enabled Machine - Issues

2 Upvotes

I have an Azure Automation Account with a Hybrid Runbook Worker Group that contains 3 Arc-Enabled machines. They've been fine for years, until this last weekend, when one of them, running Windows Server 2022 Std stopped reporting in.

I ran azcmagent show, and azcmagent check, and no errors are shown. The results for both indicate connectivity is fine. But the portal shows "3 days" since last connectivity. The hybrid worker extension is up to date at 1.3.63. I see no errors in the logs on the machine.

I verified the folder permissions on the agent package are good as well. I've restarted the services (no errors/warnings), and rebooted the machine. No luck. Should I remove and reinstall the extension? Or are there other steps I should try first?

r/MSFTAzureSupport • • Dec 01 '25

Technical Question Can not log into Azure, can't open support tickets, how to help?!

3 Upvotes

I am a new startup trying to get started on Azure and CoPilot Studio.

I signed up for the Azure Free plan. I then tried to create an account for my organization using Entra ID, so that I could access CoPilot Studio, as it does not allow one to access it with a 'personal' account.

As soon as I did this, I find I can no longer log into Azure AT ALL. I get errors like the below whenever I try to log in. Because I can no longer log into Azure, I also can not even create a support ticket - at least any method I look for requires a login, and since I have not yet gotten to the point of a real account I do not have paid support.

I have to say, as a new company just trying to get started on Azure this is a very poor experience. What do I do?

"Selected user account does not exist in tenant 'Microsoft Services' and cannot access the application '631d36ba-ddbd-4e88-807a-b8cd54f9b390' in that tenant. The account needs to be added as an external user in the tenant first. Please use a different account."

I also get this error

You don't have a billing account to redeem the credit

Got to the Azure signup portal to sign up for a new account and redeem the credit.

I also get below

{
"sessionId": "295c1fe3f3634ca6b3d44fce5724c08a",
"errors": [
{
"errorMessage": "interaction_required: AADSTS16000: User account &#39;{EUII Hidden}&#39; from identity provider &#39;live.com&#39; does not exist in tenant &#39;Microsoft Services&#39; and cannot access the application &#39;e6694c91-1590-4e35-9bb7-b865c638b9c1&#39;(Microsoft_Azure_SupportPortalExtension) in that tenant. The account needs to be added as an external user in the tenant first. Sign out and sign in again with a different Azure Active Directory user account. Trace ID: 573e0665-f31b-4089-85c5-d5e6a98e0e01 Correlation ID: 23257b7e-4240-4778-b8fa-ce0f7d1cc722 Timestamp: 2025-12-01 14:43:00Z",
"clientId": "e6694c91-1590-4e35-9bb7-b865c638b9c1",
"scopes": [
"959678cf-d004-4c22-82a6-d2ce549a58b8/.default"
]
},
{
"errorMessage": "interaction_required: AADSTS16000: User account &#39;{EUII Hidden}&#39; from identity provider &#39;live.com&#39; does not exist in tenant &#39;Microsoft Services&#39; and cannot access the application &#39;e6694c91-1590-4e35-9bb7-b865c638b9c1&#39;(Microsoft_Azure_SupportPortalExtension) in that tenant. The account needs to be added as an external user in the tenant first. Sign out and sign in again with a different Azure Active Directory user account. Trace ID: 573e0665-f31b-4089-85c5-d5e6a98e0e01 Correlation ID: 23257b7e-4240-4778-b8fa-ce0f7d1cc722 Timestamp: 2025-12-01 14:43:00Z",
"clientId": "e6694c91-1590-4e35-9bb7-b865c638b9c1",
"scopes": [
"959678cf-d004-4c22-82a6-d2ce549a58b8/.default"
]
},
{
"errorMessage": "interaction_required: AADSTS16000: User account &#39;{EUII Hidden}&#39; from identity provider &#39;live.com&#39; does not exist in tenant &#39;Microsoft Services&#39; and cannot access the application &#39;e6694c91-1590-4e35-9bb7-b865c638b9c1&#39;(Microsoft_Azure_SupportPortalExtension) in that tenant. The account needs to be added as an external user in the tenant first. Sign out and sign in again with a different Azure Active Directory user account. Trace ID: 573e0665-f31b-4089-85c5-d5e6a98e0e01 Correlation ID: 23257b7e-4240-4778-b8fa-ce0f7d1cc722 Timestamp: 2025-12-01 14:43:00Z",
"clientId": "e6694c91-1590-4e35-9bb7-b865c638b9c1",
"scopes": [
"959678cf-d004-4c22-82a6-d2ce549a58b8/.default"
]
}
]
}

r/MSFTAzureSupport • • Nov 03 '25

Technical Question Can't Sign in to Azure account

1 Upvotes

I have 2FA enabled, but i got a new phone and it signed my out of the Authenticator app. So I can't use it to authenticate. How can I fix this? Thanks!

r/MSFTAzureSupport • • Oct 31 '25

Technical Question Uncertainty about Azure egress with transit ISP routing costs

Thumbnail
3 Upvotes

r/MSFTAzureSupport • • May 22 '25

Technical Question Migrating on prem file server to Azure Files

1 Upvotes

I'm trying to use Azure Files smb file share as a mounted drive for users onsite.

I'm trying to have all traffic go through our s2s to Azure for the file share

As of right now we have an on prem ADDS with O365 and Entra Sync Connect

There is so many documentation so I thought I have set it up correctly but still getting I think fileshare permissions denied?

I have set entra groups for all users and admins to smb contributor and elevated for admin in RBAC on fileshare with ADDS configured auth in fileshare.

I set default share permission to all authenticated users as well for testing.

I set firewall on Azure files to deny all on public endpoint and setup private end point with a static IP and that is routed through s2s to on prem.

I know it's working because I can connect using the storage name / access key to file.core.windows.net

Is what I'm trying to do not possible or the wrong way I want to use on prem domain credentials to access the file share.

r/MSFTAzureSupport • • Nov 13 '25

Technical Question SSH to Azure VM suddenly stopped working, VM is healthy and NSGs allow traffic

2 Upvotes

I’m running into a frustrating issue with an Azure Linux VM:

VM was working fine via SSH a couple of days ago.

  • Now, SSH from the public fails: TCP connect failed.
  • NIC NSG is set to Allow Any → Any.

Subnet NSG: none attached.

Public IP is correctly associated with the NIC.

  • VM shows SSH daemon (sshd) is listening on port 22 internally No route table or firewall appears to block traffic.
  • VM restart has been attempted, but SSH still fails externally.

Has anyone seen this happen where SSH stops working despite all NSGs, subnet, and VM settings being correct? What are the next steps to diagnose why the packets aren’t reaching the VM from the public internet?

Edit: I hadn't been able to access the serial console and for some reason today it worked and it turns out the firewall had blocked port 22 so once i was able to gain access i was able to fix it

r/MSFTAzureSupport • • Jul 18 '25

Technical Question How do I get Trusted Signing to work?

1 Upvotes

I'm following this guide: https://learn.microsoft.com/en-us/azure/trusted-signing/quickstart?source=recommendations&tabs=registerrp-portal%2Caccount-portal%2Ccertificateprofile-portal%2Cdeleteresources-portal

But creating a Trusted Signing resource just fails with the following error:

Here is the detailed error:

{
    "status": "Failed",
    "error": {
        "code": "ResourceCreationValidateFailed",
        "message": "The resource validation failed."
    }
}

I've also tried using the command-line tool `az` but it also fails. Anyone know how to get this to work? I'm frustrated that I also paid $29 to get "support" but no one will answer me.

r/MSFTAzureSupport • • Jun 29 '25

Technical Question I cannot log in to azure

2 Upvotes

The following happens.

Sign in window appears

I enter my credentials, personal gmail account

Microsoft is asking for a 6 digit code from my authenticator

authenticator can do only 8

I can change that to generate a push notification but I honestly don't know what that push notification is for, it shows a 2 digit number on the PC screen, and I don't get anything on my phone.

And that's it. I assume somehow it thinks I'm using my work or school account, which I'm not. Not anymore. Not since december last year.

I'm a tiny bit frustrated. Somehow during this month I managed to log in and I have some stuff to pay, but I don't remember how I did it, I think I removed and recreated my account that's in the authenticator, but I don't want to do that for each login. Whenever I DO manage to log in it will be the last time I promise.

Edit re/adding account into authenticator did nothing this time. So I'm basically locked out of my account.

r/MSFTAzureSupport • • Oct 24 '25

Technical Question Problem with azure for student verification

2 Upvotes

I am having issues with the azure for students verification and I am not able to contact any customer service

r/MSFTAzureSupport • • Jan 20 '25

Technical Question Can't create Azure Account

4 Upvotes

I've been trying for 3hours.

I'm based in France and have a French valid phone number.

Using my microsoft account, I can't register for a free Azure account.

We’re unable to validate your phone number

Phone validation is required to confirm your identity and complete signup.
We’re unable to validate your phone number

I've tried on chrome, edge, with 2 different emails - my phone number is valid.

It's seems to be a common problem. I tried to raise a support request but it won't let me either saying that there's an authentication token problem.

I've tried to reach microsoft on the phone, but none of the numbers I find for France leads anywhere, just automatic answering that ask questions in circle without ever connecting me to tech support.

Is there anything I can do ?

Thanks

r/MSFTAzureSupport • • May 12 '25

Technical Question Unable to create support ticket from Azure portal

1 Upvotes

Hi I am unable to deploy web application (linux) using the same code using Azure dev ops pipeline that worked until last Wednesday. I also can't create support ticket in Azure portal despite I am in developer support plan. Help me?

r/MSFTAzureSupport • • Aug 19 '25

Technical Question Need some help getting grpc working on Azure App Service (Windows)

Post image
1 Upvotes

r/MSFTAzureSupport • • Feb 01 '25

Technical Question Azure doesn't allow to raise a ticket on "We’re unable to validate your phone number"

2 Upvotes

Hi guys :)

So, I'm trying to create a support ticket in Azure, but when I have to select the "which service are you having an issue with?" I receive an authentication issue message. I'm attempting to open a support ticket because I'm getting the error 'We’re unable to validate your phone number' when trying to create my Azure trial account.

I've seen in past posts that this issue was resolved through support, but I'm unable to create a support ticket in the Azure portal. Any guidance on what to do in this case?

Thank you very much!