Subscribe for notification
Tech

Microsoft Loses Weeks of Cloud Security Logs

Microsoft informed customers that it didn’t routinely store security records for its cloud products for two weeks in September, leaving network defenses vulnerable to breaches

“A bug in one of Microsoft’s internal monitoring agents caused a malfunction in certain agents when uploading log data to our internal logging platform,” according to a notification sent to affected clients.

The notification stated that the logging outage was not the result of a security incident and that it “only impacted the collection of log events.”

Business Insider initially disclosed the loss of log data in October. The notification’s specifics have not been extensively reported. The notifications that Microsoft sent to affected companies are likely accessible only to a handful of users with tenant admin privileges, as noted by security researcher Kevin Beaumont.

Network defenders can identify suspected intrusions by keeping track of events within a product, such as information about users signing in and unsuccessful attempts, which is facilitated by logging.

Identifying unauthorized access to the customers’ networks during that two-week interval may be more challenging due to the absence of logs.

According to the Business Insider report, The affected products are Microsoft Entra, Sentinel, Defender for Cloud, and Purview.

The notification stated that Affected customers “may have experienced gaps in security-related logs or events, potentially affecting customers’ ability to analyze data, detect threats, or generate security alerts.”

Microsoft declined to respond to inquiries regarding the logging outage; however, an executive from the company verified to TechCrunch that the incident resulted from a “operational bug within our internal monitoring agent.”

“We have resolved the matter by reversing a service change.” John Sheehan, a corporate vice president at Microsoft, stated, “We have contacted all affected customers and will offer assistance as required.”

The logging outage follows a year in which federal investigators criticized Microsoft for withholding security logs from specific U.S. federal government departments that host their emails on the company’s hardened, government-only cloud.

Investigators asserted that access to these logs could have identified a series of China-backed intrusions much earlier.

The intruders, known as Storm-0558, who China supported, breached Microsoft’s network and stole a digital skeleton key. This key granted the hackers unrestricted access to U.S. government emails stored in Microsoft’s cloud.

According to a government-issued post-mortem of the cyberattack, the State Department could identify the intrusions because it purchased a higher-tier Microsoft license that provided access to security archives for its cloud products. This license was not available to many other hacked U.S. government agencies.

Microsoft announced in September 2023 that it would begin providing logs to its lower-paid cloud accounts in response to the China-backed breaches.

Carly Page contributed a report.

Hillary Ondulohi

Hillary is a media creator with a background in mechanical engineering. He leverages his technical expertise to craft informative pieces on protechbro.com, making complex concepts accessible to a wider audience.

Disqus Comments Loading...

Recent Posts

Nishad Singh Asks for Lighter Sentence in FTX Case

Nishad Singh, the former executive of FTX, is said to have cooperated with the investigation and requested a reduced sentence…

6 hours ago

FCC Mandates Hearing Aid-Compatible Phones

The FCC has implemented new regulations requiring all mobile phones to be compatible with hearing aids, ensuring accessibility for users…

7 hours ago

Worldcoin Rebrands as World, Unveils Iris-Scanning Orb

Worldcoin, the Sam Altman-founded “proof of personhood” currency that scans eyeballs became “World” on Thursday. In San Francisco, the company…

7 hours ago

Waymo Offers $3 Credit for San Francisco Transit Rides

Riders of Waymo robotaxis in the Bay Area may accumulate a $3 credit for each trip to and from specific…

7 hours ago

ChatGPT Launches on Windows

OpenAI has launched ChatGPT for Windows, enabling users to access advanced conversational AI directly on their desktop for enhanced productivity…

7 hours ago

Meta Lays off Workers Across Several Teams

Meta confirmed in a statement to TechCrunch that layoffs were implemented on Wednesday to reallocate resources within the organization A…

7 hours ago