Skip to content

Using Managed Identity inside of a Remote (PS) Session #13703

Discussion options

You must be logged in to vote

Thank you all for this discussion.

Summary:

If a managed identity is granted to an Azure Virtual Machine, a local administrator may be able to inherit from the permissions granted to this identity and gain access to Azure resources.

Conclusions:

  • In the case a managed identity is granted to an Azure VM, only local administrator may be able to inherit from the permissions of this identity to access Azure resources from within the VM.

Important: By default, Azure VM do not have a managed identity. By default, local administrators of Azure VMs do not have access to Azure resources.

  • Customers are strongly advised to always use least privilege access principle.

    • Remote access to Azure VM …

Replies: 7 comments 2 replies

Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies

This comment has been minimized.

Comment options

You must be logged in to vote
1 reply
@dingmeng-xue
Comment options

Comment options

You must be logged in to vote
1 reply
@dingmeng-xue
Comment options

Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Answer selected by dingmeng-xue
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
3 participants
Converted from issue

This discussion was converted from issue #13703 on December 18, 2020 08:16.