Stealing Azure Managed Identity Tokens from Serverless Resources

No ratings

Presented at BSidesSATX 2026 by

Azure serverless resources like Logic Apps, Function Apps, and Automation Accounts rely on managed identities to securely access Azure services without managing credentials, making them widely trusted but high-value targets. This talk shows how attackers can extract access tokens issued to managed identities, abuse them against Azure APIs, and pivot within an environment, along with practical mitigation and detection strategies.