Security & Infrastructure Tools
Microsoft suspends dev accounts for high‑profile open source projects
Microsoft has suspended developer accounts used to sign and publish updates for several high‑profile open‑source projects—including WireGuard, VeraCrypt, MemTest86 and Windscribe—after a mandatory account verification deadline that was missed. The suspensions occurred without prior notice or an easy appeal process, preventing these teams from delivering Windows builds and security patches. Microsoft’s VP Scott Hanselman said the action followed failed verifications required by the Windows Hardware Program, but maintainers reported no warning and struggled to contact support. The issue has been highlighted in media coverage and is being addressed by Microsoft, though details remain scarce.

- Overview
- A recent action by Microsoft has blocked several developer accounts that are used to maintain high-profile open-source projects. The suspension prevents these projects from publishing new software builds and security patches for Windows users, effectively halting critical updates on Windows systems while other platforms remain unaffected.
- Reports indicate that the suspensions were implemented without prior notification to the account owners, leaving maintainers without a clear path to quickly reinstate access.
- Projects Affected
- WireGuard: a widely used VPN project, with its maintenance led by a prominent developer team.
- VeraCrypt: an on-the-fly encryption utility used for secure data protection.
- MemTest86: a RAM testing and diagnostic tool used to verify memory integrity.
- Windscribe: a VPN software suite with a substantial user base.
- Additional projects within the Windows Hardware Program ecosystem were also mentioned as affected, though specific names were not always disclosed.
- Reactions from Maintainers
- Several project teams reported difficulty obtaining direct assistance from Microsoft Support. They described receiving automated replies or bots rather than human help, which left them unable to publish Windows updates.
- Maintainers noted that Linux and macOS updates could still be released, but Windows remains the dominant platform for many users, making the Windows-side disruption particularly impactful.
- Official Explanation and Timeline
- Microsoft officials indicated that the suspend action was automatic and tied to a mandatory verification process for all partners in the Windows Hardware Program who had not completed account verification since an October 2024 deadline. The company had been emailing partners about this requirement since October 2025.
- The Hardware Dev Center described a verification process that began on October 16 and included a 30-day window. If a partner failed to complete verification within that window, their account would be automatically suspended from the Windows Hardware Program, and submissions from those accounts would be blocked.
- In late March, Microsoft stated that account verification had concluded. Accounts with a status of Rejected verification were suspended, and further submissions from these accounts were no longer permitted.
- While some maintainers reported that public outreach and media inquiries helped trigger a response from Microsoft, the company did not publicly disclose why those particular projects were not notified directly prior to the suspension.
- Impact on Updates and Maintenance
- The immediate consequence is an inability for affected projects to ship Windows updates, which can hinder security patches and critical fixes for Windows users.
- The restriction does not appear to apply to Linux or macOS updates, but the Windows platform’s large user base makes the impact disproportionately large for overall project maintenance.
- Reinstatement Efforts and Follow-up
- Developers reported attempts to contact Microsoft through multiple channels, including social media, which some stated helped elicit a response from the company.
- There is mention of an effort to reinstate suspended Partner Center accounts, with some maintainers indicating that formal outreach and engagement with journalists helped accelerate action from Microsoft.
- Broader Context and Considerations
- The incident underscores the tension between large platform verification programs and independent open-source maintainers who rely on containerized or platform-specific build pipelines.
- It also highlights the importance of clear communication channels and timely notifications when automated policy enforcement affects third-party developers.
- The situation raises questions about how critical updates for Windows-based software should be managed when verification processes are involved, and the balance between security program requirements and operational continuity for open-source projects.
- Timeline Snapshot (Key Dates)
- October 2024: Deadline established for completing account verification for participants in the Windows Hardware Program.
- October 2025: Microsoft begins sending emails to partners about the verification requirement.
- October 16 (year not specified in isolation): Verification process begins for Windows Hardware Program partners.
- 30 days from the start of verification: Automatic suspension if verification is not completed.
- March 30: Microsoft states that account verification has concluded; accounts with a Rejected status are suspended and cannot submit updates.
- Early April: Public reporting by Tech media highlights that several high-profile projects have had their publishing capabilities blocked on Windows.
- Aftermath and Next Steps for Maintainers
- The affected projects are contending with a temporary halt on Windows-based releases, while other platforms remain functional for development and distribution.
- Maintainers are pursuing reinstatement through formal channels and leveraging public visibility to prompt resolution.
- The broader development community is watching for official clarifications on notification practices, potential appeals, and any policy adjustments that could prevent similar interruptions in the future.
- Summary of Core Impacts
- Automatic suspensions tied to a Windows Hardware Program verification process can disrupt critical release cycles for open-source projects.
- Direct human support and proactive notifications appear to be inconsistent across affected teams, complicating timely remediation.
- The incident demonstrates the growing importance of robust, transparent processes when platform-centric partner programs intersect with global open-source communities.