Vulnerability Alert - Virtual Machine contains an Entra browser cookie of the user account

Carl Hansen 20 Reputation points
2024-11-26T02:08:44.8433333+00:00

Hi Team,

We received a Defender alert recently telling us that there is a Virtual Machine that contains an Entra browser cookie of a user account, providing lateral movement to a Key Vault. This happened after one of our Admin users logged in to Azure Portal within the VM. I tried to replicated this but we are not getting alerts for my account with identical privileges.

We have upgraded software in the VM and cleared cache and cookies for the affected user, but we still get the alerts. There seems to be no documentation on this issue, or how to remediate. The only recommendations in Defender are to update software in the VM, nothing about how to remove the Entra cookie.

Is anyone able to assist?

alert

Azure Key Vault
Azure Key Vault
An Azure service that is used to manage and protect cryptographic keys and other secrets used by cloud apps and services.
1,328 questions
Azure Virtual Machines
Azure Virtual Machines
An Azure service that is used to provision Windows and Linux virtual machines.
8,090 questions
Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,427 questions
{count} votes

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.