logo

IAM the Captain Now – Hijacking Azure Identity Access

ID: 1ef98bb6-5985-5e23-a255-dedbb13c833f

STIX ID: report--1ef98bb6-5985-5e23-a255-dedbb13c833f

Feed Name: TrustedSec blog

Threat Score
75/100

Date Published: 2026-04-09

Date Updated: 2026-05-01

...
...

This blog post demonstrates how misconfigured Azure IAM permissions (`roleAssignments/write`, `roleDefinitions/write`, and `federatedIdentityCredentials/write`) can be abused to escalate privileges and retrieve Key Vault secrets; it provides a lab setup, concrete Azure CLI examples, and three attack workflows: direct role assignment to grant owner-like access, creating or modifying custom roles to expand privileges, and adding OIDC federated credentials to a managed identity to authenticate via GitHub workflows and access secrets.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.