Microsoft Azure began blocking new customer tenancies this week when onboarding screens flag Iran-related sanctions exposure, after the Treasury Department refreshed Office of Foreign Assets Control guidance that cloud providers said forces tighter billing-country, beneficial-owner, and payment-rail checks, according to partner notices and Azure compliance bulletins reviewed by InfoHandle.

What changed in the OFAC refresh

Treasury’s September update clarified that U.S. persons may not provide “cloud computing services” to Iranian entities or to designated persons even when workloads run outside Iran, closing a loophole resellers said some customers interpreted as geographic routing alone. The language mirrors earlier software-as-a-service restrictions but explicitly names infrastructure, platform, and software tiers sold on consumption models.

Microsoft’s public compliance pages already barred sanctioned parties; the operational shift is at signup. Azure’s commercial onboarding now runs supplemental screening when payment instruments, domain registrants, or partner attestations suggest links to Iranian nationals, government bodies, or entities on the SDN list—even if the stated use case is research in Europe.

How Azure enforces at the tenancy boundary

Engineers at two U.S. cloud consultancies said Microsoft moved checks earlier in the funnel: new Enterprise Agreement enrollments and pay-as-you-go subscriptions tied to fresh billing accounts receive automated holds pending manual review. Existing tenancies with stable billing profiles were not mass-terminated, but expansion into new regions or higher quota tiers triggers re-screening.

Partners must re-sign distributor addenda acknowledging they will not resell Azure capacity to Iranian end users or to shell companies masking Iranian ownership. Microsoft’s partner center posted template customer questionnaires asking for beneficial-owner passports and source-of-funds declarations—paperwork midsize resellers said adds days to deals that previously cleared in hours.

Who feels it first

Universities and nonprofits with Iranian-born researchers on grants reported benign false positives when personal credit cards or .ir academic domains appeared in legacy contact records. Microsoft support channels advised migrating billing to institution-owned accounts with U.S. banking rails—a fix that does not help diaspora founders whose families remain in Tehran.

European systems integrators selling Azure landing zones to Gulf energy firms said Microsoft now asks for end-customer ownership charts when subcontractors are registered in Dubai free zones—a due-diligence step they associate with the OFAC refresh rather than generic anti-fraud.

Competitive and legal context

Amazon Web Services and Google Cloud maintain comparable sanctions policies; lawyers said the story is enforcement tempo, not a Microsoft-only stance. Still, Azure’s share among U.S. federal contractors means any onboarding friction ripples through SI partners who white-label Azure for state agencies.

Trade counsel noted Treasury retains general licenses for certain humanitarian communications tools; Microsoft’s automated holds do not always distinguish licensed categories on first pass, pushing customers into manual compliance tickets.

Engineering and data residency

Technical leads emphasized that blocking happens at the subscription and identity layer, not by inspecting VM payloads—a distinction privacy officers want documented. Azure Arc and hybrid stacks that bill through Azure marketplace SKUs inherit the same gates, affecting manufacturers who thought on-prem servers sidestepped cloud sanctions rules.

Security teams running threat hunts on Iranian APT indicators unrelated to customer identity said sanctions screening is orthogonal to SOC work—but sales cycles now stall when legal sees “Iran” in a data-protection impact assessment even for defensive cyber exercises.

What partners still cannot verify

Microsoft has not published rejection rates or median manual-review times. Partners asked for a sandbox API to pre-check corporate registries before quoting projects; Azure compliance staff said they are evaluating batch screening for large distributors but offered no date.

For Azure’s U.S. channel, the immediate effect is slower net-new logos in categories Treasury cares about—and a reminder that cloud capacity is treated as an exportable service, not a neutral pipe, whenever OFAC updates its cloud language.

Incident response and false positives

Cloud security teams said false-positive holds spiked briefly after Microsoft tuned regular expressions on domain suffixes and transliterated names. Support engineers cleared legitimate U.S. startups when founders uploaded passport scans—a process privacy officers dislike but finance teams accept as cheaper than fines.

Microsoft’s compliance center promised a weekly report to large partners summarizing hold reasons without exposing personal data, a transparency step resellers requested after losing deals with no explanation beyond “policy.”

Outlook for multinational tenants

Multinationals with Iranian employees on U.S. work visas asked whether personal dev subscriptions trigger screening when corporate HR systems list birth countries. Microsoft guidance says employment-based billing accounts should segregate personal and corporate identities—a hygiene practice many enterprises postponed during rapid cloud migration.