HomeIntelligenceBrief
VULNERABILITY BRIEF🔴 Critical Vulnerability

Azure Automation Default Setting Exposes Cross‑Tenant Identity Takeover Risk

A publicly enabled default in Azure Automation, coupled with code flaws, could let attackers assume another tenant’s identity and access its data. The issue highlights the need for SOC 2‑aligned configuration controls and continuous evidence collection.

LiveThreat™ Intelligence · 📅 July 25, 2026· 📰 darkreading.com
🔴
Severity
Critical
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
4 recommended
📰
Source
darkreading.com

Azure Automation Default Setting Exposes Cross‑Tenant Identity Takeover Risk

What Happened — A publicly‑enabled default configuration in Azure Automation, combined with a chain of code flaws, could allow an attacker to assume the identity of a different Azure tenant and access that tenant’s data, credentials, and workloads. Microsoft has issued a fix that removes the default setting and patches the underlying code issues.

Why It Matters for Compliance & Audit Readiness

  • Cross‑tenant identity takeover is a classic control‑gap scenario that SOC 2’s Change Management (CC6.1) and System Operations (CC7.1) controls are designed to prevent and evidence.
  • Continuous configuration monitoring and immutable audit trails are required to prove that default, insecure settings are identified, remediated, and never re‑introduced.
  • Verisq’s Control Mapping capability lets you map the Azure Automation setting to the relevant SOC 2 controls and automatically collect evidence of remediation for audit reviewers.

Who Is Affected — Cloud service providers, SaaS vendors, and any organization that runs workloads in Azure Automation (primarily CLOUD_INFRA and CLOUD_HOST sectors).

Recommended Actions

  • Immediately audit Azure Automation accounts for the default “Runbook Worker” setting and disable it if present.
  • Apply Microsoft’s latest security patches for Azure Automation (see KB link).
  • Map the configuration change to SOC 2 CC6.1 and CC7.1 controls in your compliance framework and capture remediation evidence in a trusted repository.
  • Enable continuous configuration monitoring (e.g., Azure Policy, Azure Security Center) to detect any re‑introduction of insecure defaults.

Source: Dark Reading – Default Azure Automation Setting Enables Cross‑Tenant Identity Takeover

Technical Notes — The issue stems from a default‑on “Hybrid Runbook Worker” configuration that trusts any Azure AD tenant, combined with insufficient input validation in the Automation service code (multiple CVE‑style flaws disclosed by Microsoft). Exploitation would allow credential harvesting and lateral movement across tenant boundaries.

📰 Original Source
https://www.darkreading.com/cloud-security/default-azure-automation-setting-cross-tenant-identity-takeover

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Misconfigurations are control gaps in disguise.

Verisq AI Trust Operations turns findings like this into mapped controls with continuous evidence, keeping your audit readiness current instead of point-in-time.

Map your controls with Verisq AI Trust Operations →