logo

Cloud Security Grey Zone: Who Owns the Risk of Managed Identities? by Kat Traxler

ID: fb241375-982b-54fa-94d0-b436d5a145b2

STIX ID: report--fb241375-982b-54fa-94d0-b436d5a145b2

Feed Name: Vectra AI Blog

Date Published: 2025-08-04

Date Updated: 2026-05-01

...
...

### Cloud Security Grey Zone — Who Owns the Risk of Managed Identities This briefing compares how AWS, Google Cloud, and Microsoft Entra ID design and manage CSP-controlled non-human identities, describes three distinct threat models (AWS confused-deputy due to missing IAM condition keys; Google Cloud service-agents creating transitive access risks because they are controlled by the provider; and Microsoft’s service principal hijacking where admins could add credentials to first-party service principals), and recommends targeted mitigations such as auditing IAM condition keys, minimizing enabled services and monitoring in Google Cloud, and monitoring/ensuring appInstancePropertyLock protections in Entra ID.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.