Rogier Dijkman
Jan 12, 2023

--

Thanks for your feedback.

The other risk is Virtual Machines, which is well known.

Except for the part that you don't need to have login permissions to the Azure VM to get an access token from the Managed Identity.

When having Virtual Machine Contributor permissions, you essentially only have the permissions to manage the VM resource.

Non the less, using the Script Command, you are still able to request the access token.

--

--

Rogier Dijkman
Rogier Dijkman

Written by Rogier Dijkman

Microsoft Security MVP | Azure | GitHub | Cloud Security Architect | Marathoner | passionate about Microsoft Security

No responses yet