„compromise a legacy non-production test tenant account and gain a foothold, and then used the account’s permissions to access a very small percentage of Microsoft corporate email accounts, including members of our senior leadership team and employees in our cybersecurity, legal, and other functions, and exfiltrated some emails and attached documents.“
Does a non-production test account usually have permission to access email accounts of the senior leadership team? Is that a security best practice?
Does a non-production test account usually have permission to access email accounts of the senior leadership team? Is that a security best practice?