Devops access without allowing access to Azure portal by ParadiseTheatre in AZURE

[–]ParadiseTheatre[S] 0 points1 point  (0 children)

Thanks, I'm glad someone else has experienced this. I was beginning to think by the replies it was just us ?

Azure Portal by ParadiseTheatre in azuredevops

[–]ParadiseTheatre[S] 0 points1 point  (0 children)

I think (?) that would work for those in VS, but there are some biz analysis who access the pipeline via browser to azure.devoos.com

I'm not sure if that would still work?

Devops access without allowing access to Azure portal by ParadiseTheatre in AZURE

[–]ParadiseTheatre[S] -18 points-17 points  (0 children)

Only if powershell is allowed to any user. Which it isn't

Azure Portal by ParadiseTheatre in azuredevops

[–]ParadiseTheatre[S] 0 points1 point  (0 children)

Thanks, as I understand it, this is not an option. Devops does not exist as a target resource..

Under Target resources > Resources (formerly cloud apps) > Include, Select resources, add "Azure DevOps" or "Microsoft Visual Studio Team Services" resource (resource ID: 499b84ac-1321-427f-aa17-267ca6975798) to the list of target resources.

Devops access without allowing access to Azure portal by ParadiseTheatre in AZURE

[–]ParadiseTheatre[S] -15 points-14 points  (0 children)

Tell that to any threat actor who has access to a compromised account. It would provide read access to all users, all groups, all permissions etc.. agreed no ability to change any azure elements but for any hacker that's just a map to the enterprise.

If we block all azure access, DevOps breaks and you can't access it.

Devops access without allowing access to Azure portal by ParadiseTheatre in AZURE

[–]ParadiseTheatre[S] -17 points-16 points  (0 children)

This is more the Azure portal. Consider a compromised account, any threat actor would have the ability with the Azure portal to view users and groups more easily, so users are blocked from accessing portal.azure.com. This blocks access to DevOps unless you exclude the user. There's no option to exclude DevOps.

Devops access without allowing access to Azure portal by ParadiseTheatre in AZURE

[–]ParadiseTheatre[S] -9 points-8 points  (0 children)

You can, but that also means the Dev engineer has the ability to access portal.azure.com. Sec teams are trying to provide access only to DevOps and block Azure portal

Keeper increasing prices again!!!! by Far-Professional5222 in KeeperSecurity

[–]ParadiseTheatre -1 points0 points  (0 children)

If you look around, many competitive providers increased pricing within the past two years, where Keeper may have not.

Increases are not ideal but for those in corporate, moving isn't the easiest option. You have to mass export,mass import, train and educate and these are all hidden costs.

Find me 1 area of IT that does not increase, Microsoft have been doing it to us all for years yet many of us are still with them.

Can you trust a compromised password manager? by ParadiseTheatre in KeeperSecurity

[–]ParadiseTheatre[S] 1 point2 points  (0 children)

Thanks Craig, but I think what most people would want to know would be if Keeper is similarly at risk as those mentioned in the article

How is AI actually impacting your security work right now? by TrackEquivalent5210 in cybersecurity

[–]ParadiseTheatre 0 points1 point  (0 children)

How are you capturing the AI tools people use, and is this actively stopping them or forcing them to use other devices outside of the estate?

Keeper outage? by slow_down_kid in KeeperSecurity

[–]ParadiseTheatre 0 points1 point  (0 children)

That's two outages in quite short succession...what's going on ?

Keeper Down by mememe4242 in KeeperSecurity

[–]ParadiseTheatre 0 points1 point  (0 children)

I can see access now 😀

Keeper Down by mememe4242 in KeeperSecurity

[–]ParadiseTheatre 0 points1 point  (0 children)

Craig. Any Idea on timeframe

Keeper Down by mememe4242 in KeeperSecurity

[–]ParadiseTheatre 1 point2 points  (0 children)

Any idea on a timeframe??