Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

In 2023, Wiz Research reported that a Microsoft Azure Active Directory (AAD) authorization misconfiguration let researchers outside Microsoft’s tenant sign in to Bing Trivia, a content-management app connected to Bing.com. They demonstrated changing an item on a Bing search carousel and, through a separate cross-site scripting (XSS) path, obtaining an Office 365 API token for their own research account. The disclosure documents a controlled demonstration—not evidence that attackers stole customer data. Microsoft fixed the reported applications in 2023.

What happened in the BingBang vulnerability

Wiz Research disclosed the issue on March 29, 2023, calling it “BingBang.” The underlying problem was not simply that Azure accepted a valid sign-in. Bing Trivia was configured as a multi-tenant application, so it could accept identities from Azure tenants other than Microsoft’s. The application still needed to decide which authenticated users were permitted to enter; Wiz found that the necessary authorization checks were inadequate. Wiz Research’s technical disclosure explains the findings.

Wiz created a user in its own Azure tenant and used that account to sign in to Bing Trivia, despite the user not belonging to Microsoft’s tenant. The researchers found content-management sections associated with Bing search carousels and homepage content. In a controlled test, they changed one item in a “best soundtracks” carousel. The altered title, thumbnail, and link appeared on Bing.com. Wiz says it reverted the change and reported the issue.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How the researchers demonstrated Office 365 access

The Bing content change and the Office 365 data access were related to the exposed application environment, but they were distinct demonstrations. Wiz investigated an XSS path in Bing work search, which used Office 365 APIs. According to the disclosure, an endpoint could create JSON Web Tokens (JWTs) for those APIs. With an injected payload, the researchers retrieved a token for their own research account and used it to access that account’s Outlook email and calendar, Teams messages, SharePoint documents, and OneDrive files.

This establishes that the researchers could access data belonging to their test account using the demonstrated path. It does not establish that a malicious actor exploited the flaw or that customer data was stolen. SecurityWeek’s contemporaneous report also covered the Bing content manipulation and Office 365 exposure: SecurityWeek, March 30, 2023.

Why multi-tenant authentication can create an authorization gap

A single-tenant application is intended to accept users from one Azure tenant. A multi-tenant application can accept tokens issued for users in other tenants as well. A token can be valid as an identity credential without proving that its holder should be allowed to use a particular application or resource. The application owner must enforce that access policy, including checking relevant token claims and deciding which users may proceed.

Rank #2
Google Search
  • Google search engine.

Wiz said the responsibility was unclear to some developers using authentication features in Azure App Service and Azure Functions. The resulting risk is a gap between authentication—establishing that a user has signed in—and authorization—deciding what that user is allowed to do. In Wiz’s words, “app developers must inspect the tokens within their code and decide which user should be allowed to log in.”

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Which other Microsoft applications were reported

Wiz said it found similar access-control misconfigurations in other Microsoft applications and reported them to the company. The named applications were:

  • Mag News
  • Centralized Notification Service API
  • Contact Center
  • PoliCheck
  • Power Automate Blog
  • COSMOS

These are applications Wiz reported and Microsoft fixed, not evidence that each was exploited or that all Microsoft applications shared the flaw.

When Microsoft fixed the reported issues

Date What Wiz reported
January 31, 2023 Wiz says it reported the Bing issue and Microsoft issued an initial fix that day.
February 25, 2023 Wiz says it reported the other vulnerable applications.
February 27, 2023 Wiz’s disclosure timeline says Microsoft began fixing the other reported applications.
March 20, 2023 Wiz says Microsoft confirmed all reported applications were fixed.
March 28, 2023 Wiz says Microsoft awarded it a $40,000 bug bounty; SecurityWeek also reported the award.

These dates describe the applications Wiz reported in 2023. They should not be read as proof that every Azure application with a similar configuration is safe today.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How Azure application owners can reduce the risk

Start by identifying applications that allow users from multiple organizations or personal Microsoft accounts, then determine whether that access is intentional. Wiz also suggested testing with an account from another tenant where appropriate. Only test applications your organization owns or is authorized to assess.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Choose controls that match the access policy

Approach When it fits What it does
Single-tenant authentication External-tenant access is not required. Limits sign-in to the intended tenant.
User assignment Only designated users should enter a multi-tenant application. Restricts access to assigned users.
Conditional Access Access should depend on organizational sign-in policies. Applies configured conditions to access decisions.
Application-side claims and token checks The application must make its own authorization decisions, especially when it remains multi-tenant. Checks token claims and enforces which users may use the app and its resources.

These controls are not interchangeable guarantees. Select and validate them against the application’s intended access model; a valid token alone should not substitute for application-level authorization.

Review sign-in evidence

Wiz said Microsoft told it that Azure AD logs were insufficient to assess past activity for this issue and recommended reviewing the applications’ own logs for suspicious logins. Owners investigating possible exposure should include those application logs rather than relying on Azure AD logs alone.

Wiz also reported that about 25% of the multi-tenant applications it scanned were vulnerable to authentication bypass. That figure is Wiz’s scan result, not an estimate for all Azure applications or cloud services. The disclosure’s broader warning was that any organization with multi-tenant Azure AD applications lacking sufficient authorization checks could face a similar class of risk.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.