Off-Prem

PaaS + IaaS

Microsoft keeps quiet amid talk of possible DDoS attack against Azure

Telemetry revealed 'anomalous spike in HTTP requests' says post-incident report


Microsoft has provided comment on an "anomalous spike" in Azure traffic at the end of last week, which sparked several hours of service disruption.

The incident took place between 15:10 and 17:10 UTC on June 9 when customers faced error notifications when trying to access the Azure portal, and also affected other services including Microsoft Entry Admin Center and Microsoft Intune.

At the time, Anonymous Sudan claimed responsibility for a DDoS attack that it alleges was behind the Azure issues.

The official version of the story, as outlined by Microsoft in a preliminary post-incident review, is that internal telemetry highlighted an "anomaly with increased request rates and the Azure portal displaying a 'service unavailable' message in multiple geographies."

"Traffic analysis showed an anomalous spike in HTTP requests being issued against Azure portal origins, bypassing existing automatic preventive measure and triggering the service unavailable response."

Subsequently, engineers across the Azure portal and networking were dispatched to make quick work of adjusting firewall rules to block the traffic, tweaking traffic throttling rules, adding more Azure portal server instances, and rebooting unhealthy Azure portal instances.

Microsoft says it is trying to make the Azure portal startup process faster and "improving our internal Azure portal monitoring to detect such indicators more quickly and efficiently."

Of Anonymous Sudan's alleged involvement, Microsoft said in a statement that it was "aware of these claims and are investigating."

"We are taking the necessary steps to protect customers and ensure the stability of our services," it added.

Readers may have some sympathy with Microsoft over the latest Azure service degradation – particularly if it was attacked – but there was likely less understanding over a previous outage of Microsoft Azure DevOps, a line of application lifecycle services that was downed for 10 hours by a typo. ®

Send us news
6 Comments

Microsoft kills classic Azure DaaS, because it isn't really Azure

Users get three-year deprecation and migration warning

Microsoft extends life support for aging Apache Cassandra 3.11 database

But only if you're ready to cozy up in Azure's abode

Microsoft attempts to woo governments with Cloud for Sovereignty preview

Sovereignty = you’ll run on Azure and you’ll be told when our engineers access your resources

From chaos to cadence: Celebrating two decades of Microsoft's Patch Tuesday

IT folks look back on 20 years of what is now infosec tradition

LinkedIn lays off nearly 700 staff, engineers to suffer the most

Time to update that resume on, er ... oh.

Microsoft says VBScript will be ripped from Windows in future release

It's PowerShell or something similar in the not too distant future

Calls for Visual Studio security tweak fall on deaf ears despite one-click RCE exploit

Two years on and Microsoft refuses to address the issue

Microsoft does not want ValueLicensing CEO anywhere near its confidentiality ring

Perpetual license case perpetually rumbles on

Imagine a world without egress fees or cloud software license disparities

UK regulator lists series of potential remedies for anti-competitive practices early on in probe

Brit watchdog slams Microsoft as it clears $69B Activision Blizzard buy

'Tactics employed by Microsoft are no way to engage with us'

Microsoft takes another run at closing Exchange brute-force security hole

Meanwhile, Exchange Online is on the fritz

Microsoft reportedly runs GitHub's AI Copilot at a loss

Redmond willing to do its accounts in red ink to get you hooked