→ Back to Home
Multi-Cloud

Why Unchecked Workload Identities and Attack Paths Cripple Enterprise Multi-Cloud Security

Microsoft released comprehensive findings from its State of Multicloud Security Risk report, evaluating cross-cloud telemetry across Microsoft Defender for Cloud, Microsoft Entra, and Purview across Azure, AWS, and GCP environments. The data indicates that 86% of organizations now operate in multi-cloud estates, but over half of cloud identities possess unrestricted permissions across cloud assets—effectively operating as 'super identities.' Crucially, while granted permissions continue to expand (increasing 22% year-over-year), only 2% of human permissions and 3% of workload permissions are ever utilized. Furthermore, the analysis surfaced more than 6.3 million exposed critical assets across estates, with the average multi-cloud organization containing 351 exploitable attack paths leading directly to high-value assets. The operational friction in multi-cloud security is no longer about perimeter firewalls; it is driven by non-human workload identities and disparate permission semantics. Workload identities—such as automated CI/CD runners, container service accounts, and serverless roles—now comprise 83% of all cloud identities, with 40% lying dormant yet fully privileged. Because each cloud provider manages access control and IAM policy structures differently, security and DevOps teams struggle to build coherent least-privilege policies. A single compromised credential in one provider often exposes high-risk paths straight into data lakes or compute clusters across an entire heterogeneous topology. This shift reflects the broader enterprise evolution from single-hyperscaler loyalty to pragmatic multi-cloud workload placement for compliance, data sovereignty, and specialized AI/PaaS features. However, while networking layers have matured through native cross-cloud interconnects and private transits, security control planes have lagged behind. Fragmented tooling forces SecOps teams to toggle between provider-native dashboards, causing alert fatigue and critical blind spots. In response, the industry is accelerating toward consolidated Cloud-Native Application Protection Platforms (CNAPP) and Cloud Infrastructure Entitlement Management (CIEM) that provide unified, cross-cloud posture assessment and continuous attack path mapping from code to runtime. For cloud architects and DevOps leads, managing multi-cloud requires immediate operational changes. First, prioritize non-human identity audits by implementing automated CIEM tools to strip over-permissioned service principles and eliminate dormant workload identities. Second, enforce centralized Cloud Security Posture Management (CSPM) with automated attack path graphing rather than relying on disparate provider alerts. Finally, standardize infrastructure-as-code (IaC) security linting and identity federation across AWS, Azure, and GCP to maintain continuous compliance before deployment.
#multi-cloud#cloud-security#iam#cnapp#devsecops
Read original source