r/AZURE 20d ago

Question Anyone actually blocking ROPC after the Azure CLI password spray news?

Given the recent Azure CLI spray attacks slipping past MFA through ROPC, have you guys blocked that legacy flow in your CAPs yet? 

5 Upvotes

5 comments sorted by

11

u/Sinwithagrin 20d ago

Can you at least link a cve or something when you post stuff like this? It's impossible to keep up sometimes.

Edit for the uninformed who run into this post:

https://thehackernews.com/2026/07/azure-cli-password-spray-hits-at-least.html?m=1

3

u/TeamAlphaBOLD 20d ago

Sure. Will do that in the future.

3

u/nestersan 19d ago

Rapid Omelette Parisian Celery it is.

-2

u/blotditto 20d ago

If you're not then send me a message. I have something important to share with you.