Disclosure of Vulnerability in Azure Automation Managed Identity Tokens

  • Thread starter Thread starter MSRC
  • Start date Start date
M

MSRC

On December 10, 2021, Microsoft mitigated a vulnerability in the Azure Automation service. Azure Automation accounts that used Managed Identitiestokens for authorization and an Azure Sandbox for job runtime and execution were exposed. Microsoft has not detected evidence of misuse of tokens. Microsoft has notified customers with affected Automation accounts. Microsoft recommends following the security best practices herefor the Azure Automation service

Continue reading...
 
Back
Top