Microsoft PKI Services: Loss of Archived Firewall logs from Retention Store
This case is a self-disclosure by Microsoft regarding a loss of approximately nine and a half months of archived firewall syslog data from a retention store in its monitoring and retention platform. Microsoft stated the issue was discovered while reviewing enhancements to the platform, and that the problem was detected on September 12, 2019. Microsoft said the misconfiguration causing the log loss was corrected within a couple of hours the same day, and that continuous monitoring and alerting for the retention part of the platform was implemented on October 7, 2019. Microsoft reported that the certificates issued during the loss timeframe were test certificates that had since expired, and that there were no problem certificates to report. Microsoft also stated that the issue was caused by human error in setting incorrect parameters for archival of firewall logs, and that periodic evidence requests had been fulfilled from the monitoring part of the platform rather than the retention part. In response to questions, Microsoft listed multiple Microsoft CA certificates active during the time of the loss and stated it performed root cause analysis and remediation, including automated monitoring/alerting and a manual check process as part of internal periodic audits. The bug was marked RESOLVED with resolution FIXED, and a Fastly participant indicated remediation was complete.
- Microsoft detected a misconfiguration that resulted in loss of archived firewall syslog data from the retention store.
- Microsoft corrected the retention-store misconfiguration within a couple of hours.
- Microsoft implemented continuous monitoring and alerting for the retention part of the monitoring and retention platform.
- Microsoft Corporation — Microsoft reported the loss of archived firewall syslog data, described detection and remediation timelines, and stated there were no problem certificates to report.
- Fastly representative — Fastly asked which Microsoft CA certificates were affected, why reporting was delayed, and whether a root cause analysis and prevention steps were performed.
- Microsoft Corporation — Microsoft answered the questions by listing CA certificates active during the loss window, explaining the reporting delay, and describing root cause analysis and remediation (automated monitoring/alerting and a manual check process).
- Microsoft Corporation — Microsoft noted an unintentional formatting issue in the middle of the response.
- Fastly representative — Fastly stated it appeared all questions were answered and remediation was complete.