Default Azure Automation Setting Enables Cross-Tenant Identity Takeover
July 24, 2026 · Dark Reading · Severity: MEDIUM
Microsoft fixed a default configuration setting in Azure Automation that was set to public-by-default, combined with code-level flaws that collectively enabled cross-tenant takeover attacks. The vulnerability allowed an attacker in one Azure tenant to gain unauthorized access to automation accounts and resources in other tenants, potentially compromising runbooks, credentials, and automated workflows across organizational boundaries. The public-by-default nature of the setting meant that many organizations were unknowingly exposed from the moment they provisioned Azure Automation resources, and the configuration would only be hardened if administrators explicitly and proactively locked it down.
Key Takeaways
- A default public-by-accessible configuration in Azure Automation enabled cross-tenant takeover between organizations.
- The vulnerability combined a misconfiguration with code flaws, allowing attackers to access automation resources across tenant boundaries.
- Public-by-default settings create widespread exposure because most organizations never review or change them.