Azure DevOps Attack Path Exposed in New DART Report
Summary
Microsoft’s latest DART cyberattack report shows how a single compromised identity was used to access Azure DevOps, alter pipelines, and harvest Kubernetes credentials. The case highlights how tightly connected identity, DevOps, and cloud environments can let attackers move far beyond source code, making stronger identity and pipeline controls essential.
Azure DevOps attack path highlights identity-driven risk
Introduction
Microsoft has published a new Cyberattack Series report detailing how threat actor Storm-3068 turned a single compromised account into broader access across development and cloud environments. For IT and security teams, the key takeaway is clear: identity, DevOps, and production systems are now so tightly connected that one account compromise can expose far more than source code.
What happened
According to Microsoft Defender Experts Cybersecurity Incident Response (DART), the attack began when Storm-3068 took over a user identity through a self-service password reset flow and registered its own authentication methods for persistence.
From there, the attacker moved into Azure DevOps and used legitimate tools and scripts to:
- Enumerate repositories, projects, pipelines, and deployment environments
- Map trusted service connections and authorized resources
- Create a malicious pipeline to harvest Kubernetes credentials
- Modify pipeline scripts to install remote access and tunneling tools
- Add stolen kubeconfig files to a repository for later cluster access
A major finding in the report is that Azure DevOps can provide attackers with a roadmap to an organization’s wider environment, including deployment paths, cloud resources, and production infrastructure.
Why this matters for administrators
This incident did not rely on malware or software exploitation. Instead, the attacker abused legitimate identity and cloud services, making the activity harder to detect with traditional endpoint-focused defenses.
For administrators, the report reinforces several important risks:
- Self-service password reset can become an attack path if not tightly monitored and protected
- Pipeline permissions matter because build and deployment workflows may have access to highly sensitive resources
- Kubernetes credentials in pipelines are high value and can enable direct access to production environments
- DevOps platforms are security boundaries and should be treated as critical infrastructure, not just developer tooling
Recommended next steps
Microsoft recommends that organizations strengthen controls across identity, DevOps, and cloud operations. Practical actions include:
- Monitor password reset activity for unusual patterns or repeated attempts
- Require phishing-resistant multifactor authentication for privileged accounts
- Limit exposure of privileged users to self-service password reset workflows
- Enforce branch protection and approval requirements for code changes
- Restrict direct commits to critical branches
- Limit who can create, modify, or run pipelines
- Apply least-privilege access across identities, DevOps platforms, and cloud resources
Bottom line
The report is a strong reminder that identities are now a primary attack path. If Azure DevOps, pipelines, and cloud infrastructure are interconnected, a compromised account can quickly become the “keys to the kingdom.” Security teams should review identity protections and pipeline governance now to reduce that risk.
Need help with Security?
Our experts can help you implement and optimize your Microsoft solutions.
Talk to an ExpertStay updated on Microsoft technologies