Evidence search
Search
Search titles, summaries, topics, providers, authors, and the full open-access corpus.
Results for “assignment”
19 publicationsGive Azure readers access to one resource group
Assign Reader without granting write access or assuming it grants data access.
Identity & access · Azure · By Cloud Security DeskRead an Azure Key Vault secret from a VM without a password
Set up one system-assigned VM identity and a vault-scoped secret permission.
Identity & access · Azure · By Cloud Security DeskGet an Azure alert when a role assignment changes
Detect successful RBAC changes and test alert delivery without expanding a production role.
Detection & response · Azure · By Cloud Security DeskConnect to Azure OpenAI without an API key
Prove Entra-based inference with a scoped runtime identity before disabling local authentication.
AI systems · Azure · By Cloud Security DeskRecover a deleted Azure Key Vault secret
Distinguish secret recovery from vault recovery and verify versioned application references.
Resilience · Azure · By Cloud Security DeskDesign application authorization before writing Cedar policies
Define business actions, trustworthy entities and tenant boundaries before writing Cedar policies, then make the application responsible for enforcing the resulting decision.
Identity & access · AWS / Cedar · By Cloud Security DeskChoose who can share an inference prefix cache
Choose the principals allowed to share prefix state, then carry that decision through request routing, offload, transfer and restore.
AI systems · vLLM / NVIDIA · By Cloud Security DeskSet explicit trust boundaries for Entra partner access
Accepting another tenant’s authentication claims is a specific trust decision, not blanket approval of its users, devices or access to your applications.
Identity & access · Microsoft · By Cloud Security DeskProve Identity Center permission changes reached every account
A permission-set change is complete only when the intended accounts, account-local policies, provisioning results and assignments have converged.
Identity & access · AWS · By Cloud Security DeskA defensible cloud patch queue starts with exploitation evidence
Join exploitation evidence to affected assets, exposure, ownership and verified remediation without turning CVSS, EPSS or a catalog entry into a complete risk score.
Detection & response · CISA / NIST / FIRST · By Cloud Security DeskEntra emergency access that survives normal sign-in failure
A second administrator account does not prove an independent recovery path. Test the credential, workstation, policy and alert dependencies together.
Identity & access · Microsoft Entra · By Cloud Security DeskMeasure SCIM offboarding at the application
A successful provisioning update proves a directory action, not the end of every application session. Define and test the application's offboarding contract.
Identity & access · SCIM / Microsoft Entra · By Cloud Security DeskBuild an Azure change record that survives the portal window
Activity Log records and resource logs answer different questions. Preserve the operation outcome, resource context and export scope needed for a later investigation.
Detection & response · Azure · By Cloud Security DeskTrace Google service account impersonation across every hop
A short-lived token can carry a broad identity. Review who can mint it, which account it represents and whether the original caller remains visible.
Identity & access · Google Cloud · By Cloud Security DeskReview the authority behind every Entra app consent
The permission name is only part of the decision. Review the access mode, resource scope, consenting authority and people who can change the application.
Identity & access · Microsoft Entra · By Cloud Security DeskInvestigate an Entra application through grants and sign-ins
A successful service-principal sign-in is one event in a larger sequence. Connect it to credential changes, permission grants and the resource involved.
Detection & response · Microsoft Entra · By Cloud Security DeskDefine the expiry boundary for Entra privileged access
PIM records activation and expiry, but the protected application still determines when changed authority takes effect. Review both sides of that boundary.
Identity & access · Microsoft Entra · By Cloud Security DeskClose the AWS sessions that survive identity shutdown
Removing a login does not by itself establish that issued AWS credentials have lost their authority. Build a revocation procedure that accounts for both.
Identity & access · AWS · By Cloud Security DeskQwen3.8-Flash-Next and GLM-5.3-Flash share a 3:1 long-context pattern
Both models replace most conventional attention layers with recurrent state and reserve sparse attention for periodic retrieval. Their differences lie in where they place capacity, how much neural computation they activate, and what their serving stacks must keep trustworthy.
AI systems · Resilience · By Umair Akbar and Ahmed Elshekh