An automated attack reportedly used a credential exposed in a public code issue to conduct reconnaissance for about 15 hours, then launched a seven-minute burst of deletion attempts against more than 100 Azure Storage accounts and Key Vaults. Resource locks prevented some of the damage, but they are not a complete security control. What defenses can realistically limit the impact when attackers—or AI-powered tools—can act faster than a human response team?
3 Answers
Immutable backups are one of the strongest recovery controls. Resource locks help prevent mistakes, but they should not be treated as protection against a determined attacker with sufficient permissions. For Key Vault, enable soft delete and purge protection, and apply similar recovery and retention safeguards to other critical data.
Use multifactor authentication for human accounts, but remember that it does not automatically protect service principals. Those identities need short-lived or federated credentials, least-privilege access, monitoring, and alerts for unusual bulk operations. Layered controls matter because no single setting will stop a fast-moving attack.
Start by preventing credentials from being exposed at all, then use workload identity federation where possible so there are no long-lived secrets to leak. Service principals should have narrowly scoped permissions—ideally only the specific resource groups and actions they need. The goal is to reduce the blast radius if an identity is compromised.

For important service identities, workload identity risk signals can also be connected to conditional access decisions, giving you another way to block or restrict suspicious activity.