Who polices your policies? Azure policy abuse for privileges escalation and persistence
ID: 487145d3-24f2-5633-960e-05bf6e8f0590
STIX ID: report--487145d3-24f2-5633-960e-05bf6e8f0590
Feed Name: Datadog Security Labs
This report examines the abuse potential of Azure Policy, showing how attackers can leverage policy effects (append, modify, deployIfNotExists) and policy assignments to disable logging, alter network rules, inject SSH keys, and deploy backdoor extensions, as well as escalate privileges via editing policy definitions and initiatives. It highlights the risks of the Resource Policy Contributor role, the prevalence of over-permissioned built-in policies, limited logging for certain effects, and recommends least-privilege configurations and monitoring of policy assignment and definition changes.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
