Microsoft Partner Center Security Alert - Action required without enough guidance

Corey Muszak 32 Reputation points
2026-08-01T15:26:17.3866667+00:00

Hello,

We received the following Security alert in Microsoft Partner Center for one of our customers:

================= MESSAGE BEGIN =================

Alert description:

We’ve detected suspicious or malicious activity in this Azure subscription. The customer of this subscription has been notified. The notification sent to the customer’s Azure Service Health is shown below. Please work with your customer to resolve this issue immediately. Once you have concluded your investigation, use the actions below to indicate if the usage was legitimate or fraudulent (unexpected).

Resolve Alert

These actions will set the alert to resolved. Important: These actions only resolve the alert, they do not take any actions against resources in the Azure subscription.

Message sent to customer

You’re receiving this notification because you’re associated with one or more Azure subscriptions that currently use affected Azure virtual machines with Trusted Launch enabled.

Microsoft has deployed a security update to Azure infrastructure. A restart is required for the updated protection to take effect on affected running virtual machines.

Action required

To activate the updated protection:

  1. Review the affected virtual machines listed in the Account information section.
  2. Schedule a maintenance window based on your operational requirements.
  3. Restart each affected virtual machine.
  4. After the restart, verify that your applications and workloads are operating as expected.

A standard virtual machine restart is sufficient. You don’t need to redeploy or re-create the virtual machine, or make application or configuration changes.

During the restart, affected workloads will experience the interruption normally associated with a planned virtual machine restart.

================= MESSAGE END =================

There is no detail on where the "Account information section" is. We see no kind of alerts within the Azure portal for this customer that has any helpful information detailing what Virtual Machines are impacted by this security alert, so we do not know what virtual machines need action. Is there any additional information that can be provided to add to this alert so we understand how to appropriately address the security issue?

Thank you!

Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
0 comments No comments

1 answer

Sort by: Most helpful
  1. Deleted

    This answer has been deleted due to a violation of our Code of Conduct. The answer was manually reported or identified through automated detection before action was taken. Please refer to our Code of Conduct for more information.

    1 deleted comment

    Comments have been turned off. Learn more

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.