Forum Discussion
Customer CUSTOMER_NAME notified of anomalous activity in Azure subscription
How do others feel about the alerts showing up in the Partner Center?
We’ve detected suspicious or malicious activity in this Azure subscription. The customer of this subscription has been notified.
What suspicious or malicious activity did microsoft detect you ask?
An important security update is available for your Windows Server Update Services (WSUS) resource(s).
That's right, there is no suspicious or malicious activity. Microsoft wants people to install an out of band security update and thought sending a notification to all azure customers was the best way to ensure that happened. Half the clients that received this alert aren't even running windows servers! Those that are running windows servers do not have the WSUS role installed.
All the clients Microsoft alerted us about to suspicious activity in their subscriptions... Don't use WSUS
We did have the pleasure of manually closing every single alert as "ignore" and I'm delighted to know that these alerts didn't count towards the security requirement to have an avg response time of less than 24h.
I thought the partner security alerts were to notify us of critical issues microsoft detected in azure subscriptions. This, does not appear to be that.
Am I missing something? thoughts?
2 Replies
- FrankWWTSCOccasional Reader
To make matters worse, the export function only includes the title of the alert and not the description details, so you cannot export the list to excel to help sort these false positives from any "actual" alerts that might be lost within.
You cannot see more than 5 alerts at a time, making scrolling through the 207 alerts i currently have a nightmare.
If you scroll to say, page 15 and click an alert, when you go back, you start back on page 1.
You cannot bulk/edit alerts, meaning every single interaction has to be manual.
The "resolution code" options are non-sensical
When the alerts ARE valid, they often do not give you enough information to ACTUALLY investigate, ie: "Cryptomining detected on VM1" - customer will ask "well we didn't do anything, what should we search for to help find this alleged cryptomining software?" - escalate to microsoft for more details who will say "sorry we cannot tell you".
Prone to false alerts: One day in 2025 Microsoft decided that Cloudflare was a cryptomining pool, creating over 1000 alerts for us over a weekend. Even after discovering this error and acknowledging the false positive, no action was taken to "undo" the alerts, so we were left to cleanup manually.
- Nick_BeacroftSteel Contributor
We had the exact same happen and none of our Azure customers use WSUS.
Many hours wasted.
These were supposed to be for fraud related alerts.
They should not be for notification to patch server, and certainly not false positives where the supposed services are not being used. Very poor from Microsoft IMO.