AI & AUTOMATION MASTER CLASS WORKSHOP
 JUL 23 | AUG 13 | AUG 27
How Top Managed Services Providers Protect Client Subscriptions from Cryptojacking — Azure Security Checklist

How Top Managed Services Providers Protect Client Subscriptions from Cryptojacking — Azure Security Checklist

Lorenzo Ciambotti

Azure gives organizations some of the most powerful and flexible infrastructure available in the cloud today. For businesses working with a skilled managed services provider, that flexibility comes with something equally valuable: a security-first foundation built before problems have a chance to develop. 

Cryptojacking, where attackers hijack cloud computing resources to mine cryptocurrency at a client's expense, is one of the more consequential threats MSPs plan for when standing up Azure environments. The good news is that it is almost entirely preventable. The following five steps are what experienced providers put in place from day one. 

Step 1: Establish Spending Boundaries at the Subscription Level 

One of the first things a knowledgeable MSP does when configuring an Azure environment is define clear cost boundaries. Azure's pay-as-you-go model is designed for flexibility, and that flexibility extends to billing. Without defined spending controls, unusual resource consumption can scale without any automatic stop. 

Top providers configure cost limit controls at the subscription level and set up alerts that notify the right people the moment spending approaches a defined threshold. Early visibility into anomalous billing patterns is one of the most reliable early signals that something is wrong, and catching it at the alert stage is far better than catching it on an invoice. 

Step 2: Enforce Multi-Factor Authentication Across the Entire Tenant 

The most common entry point for cryptojacking attacks is compromised credentials. Phishing campaigns and password-spraying attacks target Azure users specifically because a single set of valid credentials can open the door to significant compute resources. 

MFA closes that door. Experienced providers enforce multi-factor authentication for every user in the tenant, with no exceptions for administrators. Admin accounts are the highest-value target in any Azure environment, and leaving them protected by a password alone is a risk no responsible MSP accepts. Enforcing MFA across the board is also a condition of Microsoft's fraud credit policy, making it both a security and a financial protection measure. 

Step 3: Apply Azure Policy Restrictions to Limit Attack Surface 

Once inside an Azure environment, attackers move quickly to deploy large fleets of high-powered virtual machines for mining operations. A well-configured environment limits their ability to do so through Azure Policy restrictions. 

Top MSPs define which geographic regions and VM types can be provisioned within a client's subscription. High-compute VM families that have no legitimate business use for that organization are simply unavailable. This kind of proactive restriction does not interfere with normal operations, but it removes a key tool from an attacker's hands and slows the automated toolkits that cryptojacking operations rely on. 

Step 4: Enable Microsoft Defender for Cloud 

Continuous cloud security monitoring is what separates a reactive security posture from a proactive one. Microsoft Defender for Cloud provides security posture assessment, threat intelligence, and alerting across an Azure environment, giving MSPs the visibility they need to catch suspicious activity before it becomes a problem. 

Experienced providers enable Defender for Cloud as a standard part of any Azure deployment, not as an optional add-on. The threat landscape for cloud environments is active and automated. The monitoring layer needs to match that pace. 

Step 5: Audit and Decommission Unused Subscriptions 

Legacy and dormant Azure subscriptions are among the most common vectors for cryptojacking attacks. They are frequently overlooked by internal IT and finance teams, which makes them attractive targets. Attackers specifically seek out low-visibility environments where activity is unlikely to trigger any review. 

Responsible MSPs conduct regular audits of a client's full Azure tenant and decommission any subscriptions that are no longer actively managed and monitored. An unmonitored subscription is an open door, and closing it costs nothing compared to the exposure it eliminates. 

What These Steps Add Up To 

Each of these controls is straightforward on its own. What makes the difference is having a provider who implements all of them consistently, from the initial deployment forward, rather than retrofitting security after a problem surfaces. 

Cryptojacking does not exist in isolation either. The same credential theft techniques that enable these attacks, including phishing, password attacks, and OAuth abuse, are the foundation of broader threats, including ransomware campaigns that have cost businesses millions in recovery and downtime and data breaches. Organizations that build a strong Azure security foundation are protecting themselves across a wider threat landscape than any single attack type. 

Microsoft's fraud policy offers limited recourse after the fact: a one-time discretionary credit, available only if MFA was already enabled, and it can only be used once per tenant. The case for getting the configuration right from the start is straightforward. 

Working with a Partner Who Gets This 

eMazzanti Technologies has helped organizations across industries build secure, well-governed Azure environments that are designed to stay that way. As a Microsoft Solutions Partner, we bring the certified expertise and operational experience to configure these protections correctly and monitor them over time. 

If your organization is evaluating Azure or reviewing your current cloud security posture, contact eMazzanti Technologies to start the conversation.