A recent analysis demonstrated that when an AI agent authenticates using a human's Azure credentials, it inherits all permissions associated with that user. This is a common practice where engineers describe the agent as 'not having an identity yet,' but in reality, it operates with the human's identity.
The investigation found that an agent given Azure credentials could access a wide range of permissions, from two on one production store to 107 on another. This highlights a significant disparity in access levels that agents can acquire through inherited credentials.
A critical finding was the absence of audit trails in environments where the agent had the most sensitive permissions. Specifically, the environment where the agent could delete from a secure database was the only one with auditing switched off. This lack of logging means that actions performed by the agent using borrowed credentials are untraceable, posing a significant security risk.
This issue was not due to misconfiguration but was a consequence of how these systems are typically set up, where such access levels and lack of auditing were considered reasonable when only a human held the credential.
Using borrowed credentials for AI agents leads to several security issues. Attribution collapses, making it impossible to determine who or what performed an action. The agent inherits all permissions accumulated by the human, potentially granting it excessive access.
Furthermore, revoking the agent's access necessitates revoking the human's access, creating operational challenges. These outcomes are more complex than initially perceived, as demonstrated by the varying permission scopes and audit trail gaps.
The analysis also extended to properly scoped machine identities for unattended agents. Even when built correctly and scoped per resource, these machine identities exhibited similar vulnerabilities regarding audit trails and inherited permissions. This indicates a systemic issue beyond individual misconfigurations.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
An investigation into AI agents using human credentials revealed that agents inherit all user permissions, leading to significant permission scope variations and a lack of audit trails in critical environments. This practice, common in development, creates security vulnerabilities by obscuring agent actions and making revocation difficult.