How a control plane fail can help you learn about Azure security

No ratings

Presented at fwd:cloudsec 2024 by

Using a control plane bypass in Azure OpenAI as an example of when things go wrong, this talk will discuss how Azure RBAC and other Azure platform security controls work for those who have to secure Azure environments but are coming from a different cloud background. Attendees of this talk will come away with understanding differences in how permission controls work in Azure compared to AWS, other neat security controls that are natively present in Azure, using Azure permissions to find unpublished APIs, how to use the published REST APIs to discover vulnerabilities, a concrete example of why managed/built-in roles need to be carefully examined and why wildcards are bad.