All machines are destroyed by end of the tasks and will be re-created at scheduled time. Only 1 to 3 machines will have this error out of 30-40 machines created with shared NSG and DNS is out of the question as most of them working normally. Problem appearred in random machine with non-specific Pip.
Blocked Sorry, your request is a suscipious threat to the website and blocked by the defense system. Please contact the system administrator to whitelist your access if it is a false positive. Your request id is ac11000117277411084483368e1733
Got this when using firefox AND edge to visit a website.
Probably blocked by Windows Security but how can I fix it?
Blocked
Sorry, your request is a suscipious threat to the website and blocked by the defense system.
Please contact the system administrator to whitelist your access if it is a false positive.
Your request id is
ac11000117277411084483368e1733
Thank you for your help
Windows 10
Azure Virtual Machines
-
Sai Krishna Katakam 785 Reputation points • Microsoft Vendor
2024-10-01T03:15:23.5966667+00:00 Hi Lewis Lee,
Welcome to the Microsoft Q&A Platform! Thank you for asking your question here.
Can you please confirm if you are accessing the website from an Azure Virtual Machine or from a physical/local machine?
If you are using an Azure Virtual Machine, could you provide details on the operating system and any additional security configurations (like Azure Defender) in place?
Are you experiencing this issue across different machines or only on a specific environment (e.g., a virtual machine, local desktop, etc.)?
-
Lewis Lee 40 Reputation points
2024-10-01T03:31:49.4533333+00:00 Hi Sai Krishna Katakam,
accessing the website from an Azure Virtual MachineI have created more than ten VM from the same gallery image and only one out of 10 experienced this. Firefox and edge both returned the same error.
Additional information the VM is created by the same image, and same script with identical NIC, PIP, NSG creation method through the same scripts.
So there's nothing to do with the scripts for sure.
In addition, the same issue occurred in the second day I created another 10 VMs with the same script.
But the funny thing is, say the 5th VM is experienced the blocking issue yesterday, it was the 2nd VM experienced the block today. But there's no interdependences between each of them. weird!
-
Sai Krishna Katakam 785 Reputation points • Microsoft Vendor
2024-10-01T07:00:48.56+00:00 Hi Lewis Lee,
The issue might be related to security configurations or network traffic patterns affecting certain Azure VMs randomly. Even though you're using the same gallery image and script, some VMs could be flagged incorrectly due to network security settings or Azure services like Web Application Firewall (WAF) or Microsoft Defender for Cloud.
Here’s what you can do:
Check the Network Security Group (NSG) logs to see if any specific traffic from those VMs is being blocked.
If you're using a Web Application Firewall, look at its logs and adjust any rules that might be causing false positives.
Verify that DNS and network routing are consistent across all VMs.
Review any security extensions (like antivirus or Defender) that might be blocking the website access based on periodic updates.
Refer to these Microsoft resources for detailed guidance:
Network Security Groups
Microsoft Defender for CloudIf you have any further queries, do let us know. If the comment is helpful, please click "Upvote".
-
Sai Krishna Katakam 785 Reputation points • Microsoft Vendor
2024-10-04T01:07:21.14+00:00 Hi Lewis Lee,
Just checking in to see if you had a chance to review my comment on your question. Please let us know if it was helpful and feel free to reach out if you have any further queries.
If you found the information useful, please click "Upvote" on the post to let us know.
Thank You.
-
Lewis Lee 40 Reputation points
2024-11-05T07:56:02.9366667+00:00 The blocking happened since the first browser open and the first visit to that site, which prior to any pattern produced I believe. So I'm not sure if that's the scenario you mentioned. But to me... it's definitely not that complicated before the VM being blocked.
-
Lewis Lee 40 Reputation points
2024-11-05T07:56:41.8733333+00:00 All machines are destroyed by end of the tasks and will be re-created at scheduled time. Only 1 to 3 machines will have this error out of 30-40 machines created with shared NSG and DNS is out of the question as most of them working normally. Problem appearred in random machine with non-specific Pip.
-
Sai Krishna Katakam 785 Reputation points • Microsoft Vendor
2024-11-05T16:50:32.7766667+00:00 Hi Lewis Lee,
The issue might be due to website-specific defense mechanisms that sometimes flag connections based on traffic patterns or IP reputation.
Suggested Actions:
- The website’s defense system might be identifying certain requests as potential threats due to traffic patterns, IP behavior, or rate-limiting rules. Even with identical configurations, slight timing or frequency differences between VM requests can trigger these security measures randomly.
- Since you’re using non-specific Public IPs (PIPs), the website may temporarily flag or rate-limit certain IPs. Try adjusting the timing or throttling the request frequency from your VMs to see if it reduces these false positives.
- Since you have the Request ID (e.g., ac11000117277411084483368e1733), reach out to the website administrators. They may be able to analyze why specific VMs are being flagged, which could help identify the triggers and possibly whitelist your traffic if it’s safe.
If you have any further queries, do let us know. If the comment is helpful, please click "Upvote".
-
Sai Krishna Katakam 785 Reputation points • Microsoft Vendor
2024-11-06T13:20:52.4966667+00:00 Hi Lewis Lee,
Just checking in to see if you had a chance to review my comment on your question. Please let us know if it was helpful and feel free to reach out if you have any further queries.
If you found the information useful, please click "Upvote" on the post to let us know.
Thank You.
-
Lewis Lee 40 Reputation points
2024-11-06T15:07:24.1933333+00:00 The website is blocked since the VM start-up and the first browser trying to reach it. So I have no idea if anything deal with the "traffic pattern" as there's not yet a pattern at all.
-
Sai Krishna Katakam 785 Reputation points • Microsoft Vendor
2024-11-08T12:34:52.2666667+00:00 Hi Lewis Lee,
Could you share the URL of the website that is being blocked on certain VMs? Additionally, is this a public URL or a private/internal URL?
Thank you.
-
Lewis Lee 40 Reputation points
2024-11-09T10:53:39.46+00:00 smartplay.lcsd.gov.hk
public URL
-
Sai Krishna Katakam 785 Reputation points • Microsoft Vendor
2024-11-12T13:00:02.11+00:00 Hi Lewis Lee,
Thanks for sharing the details.
Based on the details you’ve shared, it sounds like the issue may be due to random IP reputation concerns or automated security measures on the website. Azure VMs use dynamic public IPs, and certain IPs from Azure’s pool can occasionally trigger blocks if they’ve been flagged by the website's security filters in the past.
To reduce the likelihood of these random blocks, I suggest configuring a static outbound IP for your VMs by using Azure NAT Gateway or Azure Firewall. This setup will ensure all VMs access the website through a consistent, trusted IP, which may help prevent the sporadic blocking.
For more information, please refer to the below documentation:
https://video2.skills-academy.com/en-us/azure/nat-gateway/nat-gateway-resource
https://video2.skills-academy.com/en-us/azure/virtual-network/ip-services/default-outbound-accessIf you have any further queries, do let us know. If the comment is helpful, please click "Upvote".
Sign in to comment
1 answer
Sort by: Most helpful
-
Lewis Lee 40 Reputation points
2024-11-06T15:09:24.7033333+00:00