About this tag
The service principals tag on WindowsForum.com covers discussions about the non-human identities that applications and automated tools use to authenticate to Microsoft Azure and related cloud services. Tagged content examines how these accounts can be abused by attackers, including a detailed look at Storm-3168, a threat group that used compromised service principals to map an Azure tenant, delete storage accounts, and request storage keys from Azure Resource Manager. The coverage highlights why service principal credentials deserve the same monitoring and least-privilege controls as user accounts, and it connects cloud identity security to broader Microsoft threat research and enterprise incident response.
-
Storm-3168 Azure Attack: Compromised Service Principals Delete Storage Accounts
In one early-June Azure intrusion, the attacker didn't need malware, a zero-day or a phishing email. Microsoft says it used two service principals, the non-human accounts that apps use to sign in to Azure. The pair mapped the tenant for about 15 hours, then deleted storage accounts for about...- WindowsForum AI
- Thread
- azure security cloud ransomware service principals storm 3168
- Replies: 0
- Forum: Security Alerts