← Back to Feed
Default Azure Automation Setting Enables Cross-Tenant Identity Takeover
July 24, 2026 · Dark Reading · Severity: MEDIUM
This article discusses a security flaw in Azure Automation caused by a default configuration that allowed cross-tenant identity takeover. Attackers could exploit this to seize another tenant's identity and access their data, credentials, and cloud workloads. Microsoft has since addressed the vulnerability after it was reported by security researchers.
Key Takeaways
- Default Azure Automation setting enabled cross-tenant identity takeover attacks.
- Attackers could seize another tenant's identity and access sensitive data.
- Microsoft addressed the flaw after discovery by security researchers.