Microsoft is warning enterprise customers that, for nearly a month, a bug caused a partial loss of critical security logs, putting companies that rely on this data to detect unauthorized activity at risk.
See also: Microsoft introduced the Surface Laptop 7 with an Intel chip

The issue was first reported by Business Insider earlier this month, which reported that Microsoft had begun notifying customers that their security logs were not being collected consistently between September 2 and September 19.
The lost logs include security data commonly used to monitor suspicious traffic, behavior, and connection attempts on a network, increasing the chances that attacks.
A preliminary post-logging incident review (PIR) sent to customers and shared by Microsoft MVP Joao Ferreirasheds further light on the issue, saying that logging issues were worse for some services, continuing until October 3.
See also: Vulnerability in Microsoft Dataverse allows privilege escalation
Microsoft's review says the following services were affected, each with varying degrees of log disruption:
Microsoft Entra: Potentially incomplete login logs and activity logs. Entra logs flowing through Azure Monitor to Microsoft Security products, including Microsoft Sentinel, Microsoft Purview, and Microsoft Defender for Cloud, were also impacted. Azure Logic Apps: Intermittent gaps in telemetry data in Log Analytics, resource logs, and diagnostics settings from Logic Apps were observed. Azure Healthcare API: Partially incomplete diagnostic logs. Microsoft Sentinel: Potential gaps in security- related logs or events , impacting customers' ability to analyze data, detect threats, or generate security alerts. Azure Monitor: Gaps or reduced results were observed when running queries based on log data from affected services. In scenarios where customers configured alerts based on this log data, the alert may have been impacted. Azure Trusted Signing: Addressed partially incomplete SignTransaction and SignHistory logs , resulting in reduced signing log volume and lower billing. Azure Virtual Desktop: Partially incomplete in Application Insights. Core AVD connectivity and functionality was not impacted. Power Platform: Minor discrepancies affecting data in various reports, including Analytics reports in the Admin and Creator portal, licensing reports, data exports to the data pool, application insights, and activity logging.

Microsoft says the logging failure was caused by an error that occurred while fixing a different issue in the company's log collection service. According to the company, although it fixed the bug by following safe development practices, it failed to detect the new problem and it took a few days to detect it.
See also: Microsoft improves passkeys support in Windows 11
Security logs are essential records that track events and activities on a computer or network. They serve as a critical tool for monitoring suspicious actions, detecting unauthorized access attempts, and identifying potential vulnerabilities. These logs provide detailed accounts of user actions, system changes, and security events, allowing IT teams to analyze patterns and proactively respond to threats. By systematically maintaining security logs, organizations can improve their cybersecurity posture and comply with regulatory requirements, ensuring data integrity and protection from breaches.
Source: bleepingcomputer
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
