Illustrative only - not an engagement finding
Long-Lived Cloud Credentials Exist in Source or Build History
Critical
See where this finding applies on the diagrams: delivery zone [planned] · CP7 workload identity federation
Illustrative only - not an engagement finding
Long-Lived Cloud Credentials Exist in Source or Build History
- Business summary
- A reusable cloud credential can remain valid after it is deleted from the latest source file because repository history and copied build outputs may still contain a working value.
- Assessment profile
- Expected fix Verification
-
-
Expected fix Revoke and rotate exposed material, then review service logs for unauthorized use during its exposed lifetimeVerification The previous credential must be rejected, and log review must cover its known exposure window
-
Expected fix Purge the value from current files, repository history, Azure DevOps output, caches and retained artifactsVerification Current files, repository history, Azure DevOps output, caches and retained artifacts must contain no copy
-
Expected fix Replace the credential with an Entra ID managed identity scoped to the required resource operationsVerification The application must operate through managed identity with only its approved resource permissions
-
Expected fix If a reusable secret is unavoidable, store it in Azure Key Vault, restrict readers and automate rotationVerification A planted test secret must block merge and release
-
Expected fix Block merge and release when scanning of source history or build output finds a credentialVerification If a Key Vault secret remains, rotation must complete without an outage and a failed rotation must alert its owner
-