Back Issues This Week → Calendar → Current Issue → Popular →

All issuesVolume 340, Issue 3IT Vendor NewsSysdig

No Single Pane of Glass: Anatomy of an Azure Permission Takeover

Sysdig, Tuesday, July 14th, 2026

Sysdig traced a full Azure tenant takeover in about an hour from one leaked service principal credential across five permission systems.

Sysdig's Threat Research Team analyzed a real Azure compromise in which a single leaked service principal credential gave attackers full tenant control in roughly an hour.

The service principal granted itself Global Administrator within about two and a half minutes, escalated to root-level User Access Administrator and harvested keys within five, then backdoored credentials on 26 additional application registrations for persistence.

Author Lydia Graslie argues the root cause is that Azure permissions live in five disjointed systems, Entra directory roles, Azure RBAC, Key Vault policies, bearer keys and Graph API permissions, with no common identifiers or unified logging.

She urges treating all five as one estate, cross-plane detection and identity-based auth.

more →  ·  More from Sysdig →