logo

Are Attackers "Passing Through" Your Azure App Proxy?

ID: 2cfbe674-6448-5b1e-8eee-205ca1973ebe

STIX ID: report--2cfbe674-6448-5b1e-8eee-205ca1973ebe

Feed Name: TrustedSec blog

Threat Score
55/100

Date Published: 2025-03-20

Date Updated: 2026-05-01

...
...

TL;DR: A demo shows that Azure Application Proxy configured with Pre Authentication set to “Passthrough” can unintentionally expose internal web resources by forwarding unauthenticated traffic to an on-premises server. The report documents forced browsing to discover paths, access to a customer portal and a Basic Auth prompt, and successful authentication using default/weak credentials, highlighting that Passthrough effectively behaves like opening a firewall port and can expose legacy apps and sensitive endpoints.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.