Azure
131 incident problems in Azure environments.
먼저 읽을 가이드
추천 문제
All problems (131)
SECURITY-330A break-glass or emergency path bypasses one identity control while another session or device rule still revokes it before the task finishes during a failover rehearsalThe emergency door opens and another control closes it before recovery is done. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.SecurityAdvanced18 minProSECURITY-168An emergency account bypasses the first control while a downstream session rule still revokes it too early during a failover rehearsalThe break-glass path escapes one identity gate and remains constrained by another. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.SecurityAdvanced18 minProCICD-094Argo CD sync succeeds but a namespace label policy silently strips the network exemption labelThe app is deployed cleanly, yet the workload breaks because a cluster policy rewrites the namespace labels the app depends on for networking.CI/CDAdvanced18 minProSECURITY-399Containment isolates egress from compromised hosts while the forensic image or memory capture workflow still depends on an outbound escrow service during a staged decommissionThe incident is contained and the evidence pipeline quietly breaks. The service still works through the primary path, but one dependency only fails when the old component is finally drained away.SecurityAdvanced18 minProSECURITY-078JIT provisioning creates duplicate accounts after the immutable identity key changesFederation remains healthy, but every login now spawns another local account because the stable identity key changed from email to a new immutable identifier.SecurityAdvanced18 minProSECURITY-1261JWT verification breaks after key rotationSecurity incident scenario used for structured troubleshooting practice.SecurityAdvanced18 minProSECURITY-1266JWT verification breaks after key rotationA planned key rotation is executed cleanly and one application still begins rejecting newly signed tokens.SecurityAdvanced18 minProSECURITY-085Session revocation works centrally but one edge node continues accepting the old JWT until its cache expiresThe revoke event is recorded correctly, yet some requests still succeed because one verifier node has not refreshed its token or key cache.SecurityAdvanced18 minProSECURITY-091SSO works but step-up MFA never triggersPrimary authentication succeeds, yet privileged actions remain exposed because the application is still reading an outdated assurance claim.SecurityAdvanced18 minProSECURITY-1215Temporary WAF bypass is removed centrally but one edge path still behaves as if the exception remainsThe source of truth is clean, yet traffic still flows through an old exception because rollout state diverged across edge nodes or configs.SecurityIntermediate18 minProSECURITY-1224WAF rollback looks complete but one hostname still enforces the old ruleA temporary block is reverted and most traffic returns to normal, but one API hostname still rejects the old pattern.SecurityAdvanced18 minProSECURITY-1219WAF rule rollback looks complete but one API hostname still enforces the old behaviorA temporary block is reverted and most traffic returns to normal, but one API hostname still rejects the old pattern.SecurityAdvanced18 minProSECURITY-1263A WAF blocks legitimate traffic only (alternate-proxy-chain-triggers-different-waf-signals)A WAF blocks legitimate traffic only (alternate-proxy-chain-triggers... focuses on reverse-proxy-security and asks the reader to isolate the key signal in Azure. A WAF rule tuned for one header and proxy shape can still fail on alternate h...SecurityAdvanced19 minProSECURITY-1268A WAF blocks legitimate traffic only (alternate-proxy-chain-triggers-different-waf-signals)A WAF blocks legitimate traffic only (alternate-proxy-chain-triggers... focuses on reverse-proxy-security and asks the reader to isolate the key signal in Azure. A WAF rule tuned for one header and proxy shape can still fail on alternate h...SecurityAdvanced19 minProSECURITY-081Conditional Access excludes the break-glass user but not the device-registration prerequisiteThe emergency account is excluded from the main policy, yet login still fails because an upstream prerequisite step is governed by a different device rule set.SecurityAdvanced19 minProSECURITY-1214CSP looks right but federated login popup still failsA CSP hardening change seems safe until popup or embedded identity flows start failing for some users.SecurityAdvanced19 minProSECURITY-1253mTLS looks correct but one client still failsOne runtime image connects successfully while another fails against the same upstream despite sharing the same root trust.SecurityAdvanced19 minProSECURITY-1248mTLS looks correct on paper but one client still failsOne client runtime connects successfully while another fails against the same upstream despite using the same trusted root set.SecurityAdvanced19 minProSECURITY-074Secure proxy strips WebSocket auth headers and the browser terminal stops connectingRegular HTTP browsing still works, but the interactive terminal path fails because the proxy policy handles upgraded connections differently from standard requests.SecurityAdvanced19 minProSECURITY-1229An IP allowlist is present at the edge but admin traffic still leaks throughThe team secures the public hostname and later discovers an alternate internal or legacy hostname still exposes the same admin interface.SecurityAdvanced20 minPro