Security News > 2024 > July > Microsoft says massive Azure outage was caused by DDoS attack
Microsoft confirmed that a nine-hour outage on Tuesday, which disrupted numerous Microsoft 365 and Azure services worldwide, was caused by a distributed denial-of-service (DDoS) attack. Affected services included Microsoft Entra, Intune, Power BI, Power Platform, Azure App Services, and others.
The company explained that their DDoS protection mechanisms were triggered, but an error in the implementation of their defenses exacerbated the attack's impact. Once the issue was identified, Microsoft made networking configuration changes and rerouted to alternate paths to mitigate the problem.
This confirmation came after initial reports attributed the outage to an "unexpected usage spike" that affected Azure Front Door (AFD) and Azure Content Delivery Network (CDN) components, leading to errors and latency issues. Microsoft plans to release a Preliminary Post-Incident Review (PIR) within 72 hours and a Final Post-Incident Review in two weeks, detailing the incident and lessons learned.
In June 2023, Microsoft also faced a significant DDoS attack by Anonymous Sudan, linked to Russia, targeting Azure, Outlook, and OneDrive services. Additionally, a widespread outage earlier this month affected Microsoft 365 customers due to an Azure configuration change. Past significant outages occurred in July 2022 and January 2023 due to ECS deployment and Wide Area Network IP changes, respectively.
News URL
Related news
- Microsoft warns Azure Virtual Desktop users of black screen issues (source)
- VEILDrive Attack Exploits Microsoft Services to Evade Detection and Distribute Malware (source)
- Microsoft patches Windows zero-day exploited in attacks on Ukraine (source)
- Microsoft 365 outage impacts Exchange Online, Teams, Sharepoint (source)
- Microsoft Fixes AI, Cloud, and ERP Security Flaws; One Exploited in Active Attacks (source)
- Phishing-as-a-Service "Rockstar 2FA" Targets Microsoft 365 Users with AiTM Attacks (source)
- Microsoft 365 outage takes down Office web apps, admin center (source)
- Microsoft enforces defenses preventing NTLM relay attacks (source)
- Europol Dismantles 27 DDoS Attack Platforms Across 15 Nations; Admins Arrested (source)
- Hackers Use Microsoft MSC Files to Deploy Obfuscated Backdoor in Pakistan Attacks (source)