Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

In 2023, a Microsoft AI researcher inadvertently put an Azure Storage link with an over-permissive Shared Access Signature (SAS) token in a public GitHub repository. Wiz Research said the link exposed 38TB of additional private data, including workstation backups, passwords, secret keys and Microsoft Teams messages. Microsoft said it revoked the token and found that no customer data was exposed.

What happened in the Microsoft 38TB data exposure?

While contributing to open-source AI learning models, a Microsoft employee inadvertently included a blob-storage URL in a public GitHub repository. The URL contained an Azure Storage SAS token—a signed credential that grants access to specified storage resources. In this case, Wiz reported that the token’s scope and permissions were broader than intended.

Wiz said the token allowed access to the entire storage account with full-control permissions, rather than limiting access to the intended files and read-only use. Depending on the granted permissions, full control can allow data to be read, overwritten or deleted. The incident was an accidental exposure caused by a publicly shared credential and an overly broad grant; Microsoft said it was not a security issue in Azure Storage or the SAS feature itself.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What data was exposed?

Wiz reported that it found 38TB of additional private data, including backups of two employees’ workstations, passwords, secret keys and more than 30,000 internal Teams messages associated with 359 Microsoft employees. Microsoft described the exposed material as backups of two former employees’ workstation profiles and internal Teams messages involving those former employees and colleagues. The 359-person figure is Wiz’s reported count; Microsoft’s public account does not independently confirm that exact figure.

Was customer data exposed?

Microsoft said its investigation found that no customer data was exposed and no other internal services were put at risk. That is Microsoft’s finding about this incident, not a general claim about the risks of SAS links.

When was the exposure reported and secured?

Date Event
June 22, 2023 Wiz reported the exposure to the Microsoft Security Response Center (MSRC).
June 24, 2023 Microsoft says it revoked the SAS token and prevented external access to the storage account.
September 18, 2023 Wiz published its disclosure, and Microsoft published its MSRC response.

Both public accounts appeared after Microsoft says it had revoked the token and blocked outside access.

Why was a SAS token in a public GitHub repository?

A SAS URL is a legitimate way to grant access to Azure Storage without sharing an account key. The URL carries signed permissions, scope and an expiry, so whoever has it can use the access it grants until it expires or is revoked. It should be treated as a secret when it grants access to private data.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The key distinction is between the access someone intends to share and what the token actually authorizes. For safer sharing, the grant should be limited to the specific file or container needed, allow only required actions such as reading, and expire as soon as practical. An account-wide token with write or delete permissions creates a much larger exposure if the URL becomes public.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How did Microsoft respond?

Microsoft says it revoked the exposed SAS token and prevented external access to the storage account on June 24, 2023. It also described GitHub secret scanning, which monitors public open-source code changes for plaintext credentials and includes Microsoft-provided detection for SAS URLs pointing to sensitive content such as VHDs and private cryptographic keys. Microsoft said it expanded detection to cover SAS tokens with overly permissive expiry periods or privileges. These controls can help identify exposed credentials, but they do not replace limiting the access granted by each token.

What can organizations learn from the incident?

  • Constrain scope: Grant access only to the specific resource needed, not an entire storage account when a narrower grant will work.
  • Use the fewest permissions: Prefer read-only access when recipients only need to retrieve data; avoid write or delete privileges unless they are necessary.
  • Set a suitable expiry: Use a short validity period appropriate to the task, rather than leaving a sharing link usable longer than required.
  • Scan public code for secrets: Secret scanning can detect credentials accidentally committed to repositories. Microsoft’s response describes detection for sensitive SAS URLs and expanded checks for overly permissive tokens.
  • Review research-data sharing: Open-source contributions and collaborative research can involve private datasets or credentials. Governance should make clear what can be shared and how storage access is granted.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.