Microsoft's 250 Million Support Records Exposed (Jan 2020): A Misconfigured Azure Database
Retrospective: this article looks back at events from January 2020, written in 2026 with the benefit of hindsight.
In January 2020, Microsoft disclosed that a customer support database containing about 250 million records had been exposed on the internet without password protection. The records covered support case analytics from 2005 to 2019.
How it happened
Security researcher Bob Diachenko discovered the exposed Elasticsearch databases at the end of December 2019. Microsoft said a change to network security group rules on December 5, 2019, had misconfigured access, and the databases were secured within about two days of being reported.
Microsoft said most personal information was automatically redacted, though some records contained data such as email addresses, IP addresses and support case details in non-standard formats that redaction missed.
Why it mattered
The incident showed that misconfiguration risk applies to cloud providers' own teams. A single network rule change, made weeks earlier, left an internal analytics store open to the internet. Microsoft published a detailed blog post, notified affected customers, and described process improvements.
Lessons for Azure customers
- Network security group changes need review and monitoring, especially rules that open access from
Internetor*. - Databases should not have public endpoints — use private endpoints and disable public network access.
- Authentication on every data store, even "internal" ones.
- Automatic redaction is helpful but imperfect. Minimize the data you keep.
- Azure Policy can deny creation of resources with public network access enabled.
In hindsight
Microsoft's transparency was praised, and the incident became a common teaching example. Exposed Elasticsearch, MongoDB and similar data stores remained a leading source of large data leaks throughout the decade — usually discovered by researchers scanning the internet.
- How to Prevent Public Database Exposure With Azure Policy and Private Endpoints How-To & Hardening
- Detecting Exposed Cloud Database: Defender for Cloud and Sentinel KQL Detection & Response
- CIO Brief: If Microsoft Can Misconfigure Azure, So Can You CIO Briefings