Employee downgraded me to owner, stole keys

Amanda Besemer Sampson 25 Reputation points
2025-06-09T22:55:54.57+00:00

Help! I am the rightful owner of my server and app, and a rouge contractor just set me as owner, set himself as root and downloaded keys.

We cannot access our app, code, databases. How do I get access to be the General Administrator and reset all keys. I cannot find a phone number for Azure access help. I have developer-level support.

My goals are to

  1. Become the General Administrator of our Azure server, databases, apps
  2. Replace the keys (he downloaded backdoors to everything)
Azure Role-based access control
Azure Role-based access control
An Azure service that provides fine-grained access management for Azure resources, enabling you to grant users only the rights they need to perform their jobs.
949 questions
0 comments No comments
{count} votes

Accepted answer
  1. Alex Burlachenko 9,085 Reputation points
    2025-06-10T09:05:29.3966667+00:00

    hi there Amanda, wow, that's a messed up situation.....

    for azure specifically, if u still have any access at all (even just developer level), u can try to reclaim admin rights. go to azure active directory roles and administrators in the portal. look for 'global administrator' role assignments. if u see that contractor there, u might be able to remove them if u have privilege management rights.

    since he took the keys, u need to rotate ALL of them immediately. check azure key vault first, regenerate every single key, secret and certificate. yes, it's a pain, but better safe than sorry.

    pls check if multi factor authentication was bypassed. turn it on for all admin accounts if it's off. this might help in other tools too.

    would u like an general advice? if u use any other cloud services, do the same thing there. rotate keys, check admin lists, enable mfa everywhere. worth looking into setting up privileged identity management for the future so this doesn't happen again.

    aha, and about azure support, since u have developer level, u can open a ticket in the portal. they might help escalate this. use the word 'security breach' in the ticket, it sometimes gets faster attention ;D

    good luck! hope u kick that contractor out soon :))

    Best regards,

    Alex

    and "yes" if you would follow me at Q&A - personaly thx.
    P.S. If my answer help to you, please Accept my answer
    PPS That is my Answer and not a Comment
    

    https://ctrlaltdel.blog/


0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.