Identiverse
register for 2026
CyberRisk Alliance
The Event Workshops About Us
Attending Companies NHI Pavilion
Partners Speakers Sponsors
Topics Venue VIP Program Women in Identity Summit
AI and Identity Continuous Identity Non-Human Identity
Personal Identity SANS Executive
Advisory Board Blog
Media Press Releases Profiles in Action
Videos Webinars Who We Are
Identiverse
Home
The Event
Attending Companies NHI Pavilion Partners Speakers Sponsors Topics Venue VIP Program Women in Identity Summit
Workshops
AI and Identity Continuous Identity Non-Human Identity Personal Identity SANS Executive
About Us
Advisory Board Blog Media Press Releases Profiles in Action Videos Webinars Who We Are
Identiverse 2025 • Masterclass
Hidden Dangers in Azure: Over-Privileged Roles and API Vulnerabilities
Back to Main Agenda
Tuesday, June 3
Breakers L
2:30 pm - 3:20 pm
Ariel Simon
Security Researcher
Token Security

Azure is a widely used cloud platform, supporting critical infrastructure for major organizations globally. Its Role-Based Access Control (RBAC) model simplifies identity and permissions management by offering predefined, built-in roles. However, managing permissions at scale is complex, and even seemingly trusted, built-in roles can introduce unexpected risks.

This session explores the Azure RBAC model and demonstrates the critical risks of over-privileged roles that grant excessive permissions beyond their intended scope, in addition to an Azure API vulnerability that attackers can exploit to leak secrets. We demonstrate how combining these issues can lead to cloud infrastructure breaches and on-premise network access, posing catastrophic consequences for organizations.

The session concludes with actionable strategies to fortify identity security, ensuring that organizations can maintain robust control over their cloud identities while mitigating the risks that are often overlooked.

PowerPoint PDF

Ways to stay in touch
Attendee Info & Inquiries
Sponsor Customer Service
Sponsorship & Exhibition Sales
Identiverse
Stay informed on the latest event updates
Follow us on
LinkedIn X Facebook
Hosted by CyberRisk Alliance
© 2025 identiverse • Privacy Policy • Terms of Use
register for 2026