Informa TechTarget | SearchSecurity Cybersecurity Dive InformationWeek Channel Dive Explore our brands Dark Reading Resource Library Black Hat News Omdia Cybersecurity Advertise NEWSLETTER SIGN-UP Cybersecurity Topics World The Edge DR Technology Events Resources СLOUD SECURITY IDENTITY & ACCESS MANAGEMENT SECURITY VULNERABILITIES & THREATS NEWS News, news analysis, and commentary on the latest trends in cybersecurity technology. Default Azure Automation Setting Enables Cross-Tenant Identity Takeover Microsoft addressed a public-by-default configuration and chain of code flaws in Azure Automation which could have let attackers seize another tenant's identity and access other tenants' data, credentials, and cloud workloads. Jeffrey Schwartz,Contributing Writer July 24, 2026 3 Min Read SOURCE: SOPA IMAGES LIMITED VIA ALAMY STOCK PHOTO A critical vulnerability in Microsoft's Azure Automation service could have exposed accounts to cross-tenant identity takeovers due to a default setting that could have made account identities public. Azure Automation is widely used by Microsoft internally and by enterprises running Azure for DevOps, resource deployment, patching, and secrets rotation using scripted runbooks tied to embedded managed identities. Shay Shavit, a senior security researcher on Microsoft's Azure Networking Security Research team, discovered the vulnerability last year and reported it to the Microsoft Security Response Center (MSRC), which issued an advisory. Azure Automation Elevation of Privilege Vulnerability (CVE-2025-29827), which was assigned a CVSS score of 9.9, allows an attacker with access to their own Azure Automation account to breach the trust boundary and assume another tenant's automation identity. This would enable them to create or modify automation scripts and access sensitive configuration data or credentials stored in Azure Automation accounts. A successful attacker could also create, change, or delete resources across an organization's cloud workloads. Related:Google Bets 'Agentic Defense' Strategy Can Outpace Attackers Shavit tells Dark Reading that there have been no known exploits of the vulnerability, but in his demonstration at next month's Black Hat USA conference in Las Vegas, he plans to show how the default configuration poses a risk to Microsoft and its customers. The default setting for Azure Automation identities is no longer public, Shavit says. "At the time, the default for an automation account was to be made public, at least for the endpoint, which we exploited," he explains. "Hence, that's why this was kind of messy, because when the default is public, then you can access a lot of accounts, potentially, of course." Shavit says he and his research team selected Azure Automation as a research target because its accounts typically hold privileged identities, and then worked to breach the trust boundary between the service and those identities. Once an attacker breaches the identity, they can access other accounts. "It's the endgame, because if you have a strong enough identity, you're the king in the world," he says. "You don't really need to continue your exploitation; you can do whatever you want, either in the portal, in the CLI [or] in the APIs. So that's what we successfully achieved." Even though the default setting was changed, Shavit recommends that organizations avoid surfacing anything external unless there’s a specific need to do so. Organizations can also lower their risk by auditing the scope of identities and tokens assigned to cloud automation accounts. Related:Post-Quantum Web Could be Safer, Faster Shavit says this vulnerability is an example of how subtle misconfigurations and logic flaws can be chained to enable high-impact attacks. The exploit chain consisted of three distinct flaws, he notes: the default configuration that made Azure Automation accounts publicly accessible, plus two separate code-level bugs. Shavit's finding is not the first vulnerability discovered in the Azure Automation service. In 2021, researchers at Orca Security discovered a flaw that could exfiltrate managed identity tokens from a shared sandbox server. At that time, Orca reported the vulnerability, dubbed AutoWarp, to Microsoft's Security Response Center (MSRC). Microsoft publicly disclosed the issue in March 2022 and stated that it had not detected any evidence of token misuse. Shavit says that while the two vulnerabilities share the same goal — extracting a victim's managed identity — the attack chains differ. AutoWarp exploited the service's code-execution component to establish a reverse shell, whereas Shavit’s discovery doesn’t affect code execution. While Orca described AutoWarp as critical, it never received a CVE identifier and doesn't appear in the National Vulnerability Database (NVD). Related:Lone Attacker Uses AI to Breach AWS Cloud Environment in 72 Hours Nevertheless, Shavit believes the research underscores a broader shift in cloud risk. "Identities in cloud environments have become a very focal point because they facilitate and enable an attacker to do so much when one is compromised," he says. For defenders, he suggests they avoid evaluating vulnerabilities in isolation and instead map the paths that connect them, rather than assuming a single low-severity bug poses little risk on its own. "Think about the chain — think about the attack path." Black Hat USA AUG 1, 2026 TO AUG 6, 2026 | MANDALAY BAY CONVENTION CENTER, LAS VEGAS, USA The premier cybersecurity event of the year returns to Mandalay Bay with a re‑engineered, six‑day program built to ignite innovation, push boundaries, and bring the global security community together like never before. This year’s event features four days of immersive, expert‑led Trainings (August 1–4), followed by Summit Day on Tuesday, August 4, and a two‑day main conference packed with groundbreaking Briefings, open‑source tool demos in Arsenal, a dynamic Business Hall, and unlimited learning & networking opportunities. Use code: DARKREADING to save $200 on a Briefings pass or $100 on a Business pass. GET YOUR PASS Read more about: Black Hat News About the Author Jeffrey Schwartz Contributing Writer Jeffrey Schwartz is a journalist who has covered information security and all forms of business and enterprise IT, including client computing, data center and cloud infrastructure, and application development for more than 30 years. Jeff is a regular contributor to Channel Futures. Previously, he was editor-in-chief of Redmond magazine and contributed to its sister titles Redmond Channel Partner, Application Development Trends, and Virtualization Review. Earlier, he held editorial roles with CommunicationsWeek, InternetWeek, and VARBusiness. Jeff is based in the New York City suburb of Long Island. Want more Dark Reading stories in your Google search results? ADD US NOW More Insights Industry Reports The State of Cloud Security: The Latest Challenges How Organizations Are Managing Incident Response How Enterprises Are Developing Secure Applications Inside RSAC 2026: security leaders reveal the risks redefining your defense strategy Essential News & Insights from Black Hat USA 2025 Access More Research Webinars Prevention at Machine Speed: Hunting Beyond Known Detections 0-Day to 10x Discovery: Security at the Speed of Mythos When AI Becomes an Insider: Rethinking Risk in Critical Infrastructure Governing the Agent; Identity Security in the Age of Autonomous AI Securing the AI Era: Shadow AI, AI Agents, and Why AI Detection and Response Changes Everything More Webinars You May Also Like СLOUD SECURITY APT41 Delivers 'Zero-Detection' Backdoor to Harvest Cloud Credentials by Elizabeth Montalbano APR 13, 2026 СLOUD SECURITY The Cloud Edge Is the New Attack Surface by Robert Lemos SEP 17, 2025 СLOUD SECURITY Phishing Empire Runs Undetected on Google, Cloudflare by Elizabeth Montalbano SEP 04, 2025 СLOUD SECURITY DARPA: Closing the Open Source Security Gap by Alexander Culafi AUG 21, 2025 Latest Articles in DR Technology ENDPOINT SECURITY Agentic AI Challenges Progress in Confidential Computing JUL 23, 2026 IDENTITY & ACCESS MANAGEMENT SECURITY Flaws in Passkey Implementation Show Old Attacks Still Work JUL 22, 2026 CYBERSECURITY OPERATIONS Remediating Vulnerabilities With LLMs: Inside Ivanti's Automation Push JUL 20, 2026 СLOUD SECURITY Google Bets 'Agentic Defense' Strategy Can Outpace Attackers JUL 17, 2026 Read More DR Technology Discover More Black Hat Omdia Working With Us About Us Meet the Editors Advertise Reprints Join Us NEWSLETTER SIGN-UP Follow Us Copyright © 2026 TechTarget, Inc. d/b/a Informa TechTarget. This website is owned and operated by Informa TechTarget, part of a global network that informs, influences and connects the world’s technology buyers and sellers. All copyright resides with them. Informa PLC’s registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. TechTarget, Inc.’s registered office is 275 Grove St. Newton, MA 02466. Home| Cookie Policy| Privacy| Terms of Use Your Privacy Choices