No single pane of glass: Anatomy of an Azure permission takeover
ID: 6d22ad11-6d3d-5578-810f-ae98584fb876
STIX ID: report--6d22ad11-6d3d-5578-810f-ae98584fb876
Feed Name: Sysdig Blog
**Executive summary:** The Sysdig Threat Research Team analyzed an Azure tenant takeover that began with a leaked non-human identity (service principal) and, within hours, yielded Global Administrator privileges, subscription-level Owner access via elevateAccess, resource-local Key Vault access-policy self-grants, and theft of bearer keys (storage and Event Hub), with persistence implanted across 26 application registrations; the report highlights five disjoint permission planes (Entra directory roles, Azure RBAC, Key Vault access policies, identity-less bearer keys/SAS, and Graph API application permissions), the visibility gaps between them, and prescribes concrete mitigations including cross‑plane inventorying, treating NHIs as first-class identities, alerting on cross-plane bridges (e.g., elevateAccess, listKeys, access policy writes), disabling shared keys where possible, and enabling and centralizing diagnostic logs and telemetry.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
