Storm-3168 reportedly gained access through a credential exposed in a public issue, spent about 15 hours performing automated reconnaissance, and then launched a seven-minute burst of deletion attempts against more than 100 storage accounts and Key Vaults. Resource locks prevented some of the damage, but they are not a complete security control. What protections can realistically withstand attacks that move faster than a human response?
3 Answers
Immutable backups are one of the strongest recovery controls. Resource locks can help, but they mainly protect against accidental changes and should not be treated as a security boundary. Enable soft delete and purge protection for Key Vaults, and make sure backups cannot be altered or deleted by the same identity used to manage production resources.
Start by eliminating exposed credentials, then use workload identity federation where possible so long-lived secrets are not sitting in code or public systems. Service principals should be tightly scoped to only the subscriptions, resource groups, and actions they actually need. That limits the blast radius if one is compromised. For critical workloads, workload identity risk signals can also be incorporated into conditional access decisions.
The practical answer is defense in depth: remove leaked secrets, use phishing-resistant MFA for human accounts, prefer short-lived federated credentials for workloads, enforce least privilege, and monitor for unusual destructive activity. No single control will reliably stop an automated attack moving at machine speed; the goal is to reduce access, slow the attacker, and preserve recovery options.

Related Questions
Biggest Problem With Suno AI Audio
How to Build a Custom GPT Journalist That Posts Directly to WordPress