Off-Prem

PaaS + IaaS

Azure VMs ruined by CrowdStrike patchpocalypse? Microsoft has recovery tips

Have you tried turning it off and on again, like, a bunch?


Updated Did the CrowdStrike patchpocalypse knock your Azure VMs into a BSOD boot loop? If so, Microsoft has some tips to get them back online.

It's believed that a bad channel file for CrowdStrike's endpoint security solution Falcon caused its Sensor active detection agent to attack its host. That's caused Windows machines around the world to become even less useful and wreaked havoc at airports, hospitals, emergency services and in countless unexpected places. 

It's not believed that the CrowdStrike failure was related to the other Azure outage yesterday, so if you're recovering from one hopefully you didn't have to deal with the other. If your VMs were borked by Falcon, however, then read on.

Just keep booting

We'd tell you it's a joke, but it's not: Microsoft's top piece of advice to fix your broken Azure VMs is to turn them off and on again - repeatedly. No, even more than that.

"We have received reports of successful recovery from some customers attempting multiple Virtual Machine restart operations on affected Virtual Machines," Microsoft said on its Azure status page as of writing. "Several reboots (as many as 15 have been reported) may be required, but overall feedback is that reboots are an effective troubleshooting step at this stage." 

Microsoft says affected users can reboot their VMs in the Azure portal, or by using Azure CLI or Azure Shell. 

It's always a great situation when mitigation starts with "reboot and pray." 

Of course, that's not going to help everyone, and from there the steps are largely similar to what's been reported by other people, like CrowdStrike's head of threat hunting, Brody Nisbet: You gotta do it manually.

First, if you have a backup from before 1900 UTC yesterday, just restore that. If your backup habits are lax, then you're going to have to repair the OS disk offline, which will be more difficult for those with encrypted disks.

Once you've successfully attached a recovery disk, Microsoft says customers need to delete Windows/System/System32/Drivers/CrowdStrike/C00000291*.sys, the same recommendation Nisbet made for other affected users. 

Unfortunately, even that might not work, Nesbit said - here's hoping your systems don't fall into that category.

Rebooting has been recommended as a solution largely to give the machine a chance to try to contact CrowdStrike servers and retrieve the fix. Unfortunately, when you're stuck in a boot loop this isn't very feasible. For those unable to boot into Windows, be it on a VM or physical machine, the Internet Storm Center has recommended booting into safe mode with networking, and then following the steps to delete the offending file. ®

Updated at 1551 UTC on July 19, 2024, to add

CrowdStrike's notice page for the outage has been updated to add more recovery options, as well as specific steps for AWS users and those whose Windows VMs are secured via Bitlocker.

Send us news
65 Comments

How Windows got to version 3 – an illustrated history

With added manga and snark. What's not to like?

Microsoft preps for a year of enterprise-impacting M365 retirements

Hey administrators – buckle up. 2025 is going to be a wild ride

Microsoft declares 2025 'the year of the Windows 11 PC refresh'

Slumping market share, unwanted features ... no, it's the consumers who are wrong!

Azure, Microsoft 365 MFA outage locks out users across regions

It's fixed, mostly, after Europeans had a manic Monday

How the OS/2 flop went on to shape modern software

Even Microsoft's lead architect misunderstood the failure

Google snags ex-Microsoft exec to helm cloud in the UK

Maureen Costello hopes to 'empower' businesses with AI

Microsoft’s latest on-prem Azure is for apps you don’t want in the cloud, but will manage from it

Azure Local is about hybrid management, not hybrid resource pools, and is catching up with virtual rivals

Microsoft fixes under-attack privilege-escalation holes in Hyper-V

Plus: Excel hell, angst for Adobe fans, and life's too Snort for Cisco

Microsoft tests 45% M365 price hikes in Asia-Pacific to see how much you enjoy AI

Won’t say if other nations will be hit, but will ‘listen, learn, and improve’ as buyers react – so far with anger

Microsoft sues 'foreign-based' cyber-crooks, seizes sites used to abuse AI

Scumbags stole API keys, then started a hacking-as-a-service biz, it is claimed

Windows Insiders can now turn on Administrator Protection from settings

Security feature widens out to more Windows 11 users, including those at home

New Outlook marches onto Windows 10 for what little time it has left

Users of doomed operating system to receive unloved app via an update