A cloud-native solution that protects workloads across hybrid and multi-cloud environments with threat detection and security recommendations
Microsoft Partner Center Security Alert - Action required without enough guidance
Hello,
We received the following Security alert in Microsoft Partner Center for one of our customers:
================= MESSAGE BEGIN =================
Alert description:
We’ve detected suspicious or malicious activity in this Azure subscription. The customer of this subscription has been notified. The notification sent to the customer’s Azure Service Health is shown below. Please work with your customer to resolve this issue immediately. Once you have concluded your investigation, use the actions below to indicate if the usage was legitimate or fraudulent (unexpected).
Resolve Alert
These actions will set the alert to resolved. Important: These actions only resolve the alert, they do not take any actions against resources in the Azure subscription.
Message sent to customer
You’re receiving this notification because you’re associated with one or more Azure subscriptions that currently use affected Azure virtual machines with Trusted Launch enabled.
Microsoft has deployed a security update to Azure infrastructure. A restart is required for the updated protection to take effect on affected running virtual machines.
Action required
To activate the updated protection:
- Review the affected virtual machines listed in the Account information section.
- Schedule a maintenance window based on your operational requirements.
- Restart each affected virtual machine.
- After the restart, verify that your applications and workloads are operating as expected.
A standard virtual machine restart is sufficient. You don’t need to redeploy or re-create the virtual machine, or make application or configuration changes.
During the restart, affected workloads will experience the interruption normally associated with a planned virtual machine restart.
================= MESSAGE END =================
There is no detail on where the "Account information section" is. We see no kind of alerts within the Azure portal for this customer that has any helpful information detailing what Virtual Machines are impacted by this security alert, so we do not know what virtual machines need action. Is there any additional information that can be provided to add to this alert so we understand how to appropriately address the security issue?
Thank you!
Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
1 answer
Sort by: Most helpful
-
Deleted
This answer has been deleted due to a violation of our Code of Conduct. The answer was manually reported or identified through automated detection before action was taken. Please refer to our Code of Conduct for more information.
1 deleted comment
Comments have been turned off. Learn more