Join our Newsletter — 33% off our NHI Course
Home› NHI Breaches› Microsoft SAS Token Exposure 2023: How One Over-Permissive…
Breach analysis Incident: 20 Jul 2020

Microsoft SAS Token Exposure 2023: How One Over-Permissive Link Exposed 38TB of Internal Data

← All NHI breaches
By Lalit Choda, NHI Mgmt Group Updated 29 September 2026 8 min read
On this page

In June 2023, Wiz researchers scanning for exposed cloud storage found a GitHub repository from Microsoft's AI research division, robust-models-transfer, that told readers to download AI models from an Azure Storage URL. The URL carried a shared access signature (SAS) token, a signed link that grants access to storage. It had been set to cover the entire storage account rather than one file, with "full control" permissions instead of read-only, and, after an October 2021 update, an expiry date of 2051. The account held 38TB of additional private data, including disk backups of two former employees' workstations with secrets, private keys, passwords and more than 30,000 internal Microsoft Teams messages. The token had been public since July 2020. Microsoft revoked it two days after Wiz's report and says no customer data was exposed and no other services were put at risk.

Key takeaways

  • A Microsoft researcher published a storage URL with an embedded SAS token in a public GitHub repository in July 2020, to share open-source AI models.
  • The token covered the whole storage account, granted full control rather than read-only access, and was later extended to expire in 2051, according to Wiz.
  • The account held 38TB of private data, including workstation backups with secrets, private keys, passwords and over 30,000 Teams messages from 359 employees.
  • Microsoft's own secret scanning had flagged the URL but marked it as a false positive; Microsoft fixed that and revoked the token on 24 June 2023.
  • The identity lesson: signed URLs are credentials, and a long-lived, over-scoped one shared publicly is an open door that nobody can see in an inventory.

At a glance

OrganisationMicrosoft (AI research division)
WhenToken public from 20 July 2020; reported by Wiz 22 June 2023; revoked 24 June 2023; disclosed 18 September 2023
AttackerNone known. Found by Wiz Research
Entry pointAn Azure Storage SAS URL published in the public robust-models-transfer GitHub repository
Identities abusedAn account-level SAS token with full control permissions and a 2051 expiry; secrets, private keys and passwords stored in the exposed workstation backups
Impact38TB of private data exposed, including workstation backups and Teams messages; no customer data exposed and no misuse reported, according to Microsoft
CategoryNHI. Incident class: exposure (over-permissive token public for three years, no confirmed misuse)

What happened

Wiz's research team was scanning the internet for misconfigured storage containers when it found robust-models-transfer, a repository belonging to Microsoft's AI research division that provides open-source code and AI models for image recognition. The repository instructed readers to download models from an Azure Storage URL. "However, this URL allowed access to more than just open-source models. It was configured to grant permissions on the entire storage account, exposing additional private data by mistake," Wiz wrote.

A SAS token is a signed URL that grants access to Azure Storage data. Its scope, permissions and expiry are chosen by whoever creates it, on the client side, so the token is not tracked as an Azure object. This one was an account SAS: it covered the whole storage account, which held 38TB of data, and it was "misconfigured to allow 'full control' permissions instead of read-only," meaning anyone could also delete or overwrite files. Wiz noted that the models were in a format prone to code execution, so an attacker could have tampered with them. The token was first committed on 20 July 2020 with an expiry of 5 October 2021; on 6 October 2021 its expiry was updated to 6 October 2051.

Wiz reported the issue to Microsoft on 22 June 2023. Microsoft's Security Response Center revoked the token and blocked external access to the storage account on 24 June. "Data exposed in this storage account included backups of two former employees' workstation profiles and internal Microsoft Teams messages of these two employees with their colleagues," Microsoft wrote. "No customer data was exposed, and no other internal services were put at risk because of this issue." Wiz described the backups as containing "passwords to Microsoft services, secret keys, and over 30,000 internal Microsoft Teams messages from 359 Microsoft employees."

Microsoft also disclosed that its own historical rescans of public repositories "detected the specific SAS URL identified by Wiz in the 'robust-models-transfer' repo, but the finding was incorrectly marked as a false positive." It fixed that root cause and expanded GitHub secret scanning to flag any SAS token with overly permissive expiry or privileges. Both companies published on 18 September 2023.

Timeline

DateEvent
20 July 2020The SAS token is first committed to GitHub, with an expiry of 5 October 2021.
6 October 2021The token's expiry is updated to 6 October 2051.
22 June 2023Wiz Research finds the exposure and reports it to Microsoft.
24 June 2023Microsoft revokes the token and blocks external access.
16 August 2023Microsoft completes its internal impact investigation.
18 September 2023Wiz and Microsoft publish.

How it happened: the identity attack path

  1. Token created for sharing. A researcher generated a SAS token to let the public download AI models.
  2. Over-scoped and over-privileged. The token covered the whole storage account with full control, not a single container with read-only access.
  3. Published in code. The URL containing the token was placed in a public GitHub repository.
  4. Effectively permanent. Its expiry was extended to 2051, and account SAS tokens cannot be listed or revoked individually.
  5. Detection missed. Microsoft's scanning flagged the URL but it was marked a false positive, so the exposure lasted nearly three years until Wiz reported it.

Impact

  • Exposed: 38TB of private data, including backups of two former employees' workstations with secrets, private keys and passwords, and Teams messages.
  • Integrity risk: full control permissions meant files could have been changed or deleted, including the shared AI models.
  • Misuse: none reported; Microsoft says no customer data was exposed and no other services were put at risk.

What this means for NHI governance

A SAS token is a credential that looks like a link. Wiz highlighted why account SAS tokens are hard to govern: they are generated on the client side, so there is no record they exist; they can be given any scope and an expiry decades away; and the only way to revoke one is to rotate the account key, which breaks every other token signed with it. That combination made a sharing link into a three-year exposure that nobody could see in an inventory.

The lessons generalise to any signed URL or bearer token. Scope to the smallest resource, grant read-only unless write is essential, keep expiry short, share from dedicated storage and treat the link as a secret. Detection only helps if findings are triaged well: here, the scanner worked and the triage did not. See our Secrets Management Guide and Cloud PAM and CIEM Guide.

Recommendations

  • Avoid account SAS for external sharing. Use a service SAS with a stored access policy or a user delegation SAS, which can be revoked and audited.
  • Share from dedicated storage. Keep public or partner data in its own storage account so an over-scoped token exposes nothing else.
  • Set short expiry and least privilege. Microsoft recommends one hour or less for SAS URLs, scoped to the smallest set of resources, read-only where possible. See our Secrets Management Guide.
  • Scan public code for signed URLs and triage findings carefully. A true positive marked false is as bad as no scan. See the Leaked Credential Response Playbook.
  • Limit who can list storage account keys. New account SAS tokens cannot be created without the key. See the Cloud PAM and CIEM Guide.

Frequently asked questions

What did Microsoft expose in the 38TB leak?

Backups of two former employees' workstations, which contained secrets, private keys and passwords, and more than 30,000 internal Teams messages. Microsoft said no customer data was exposed.

What is a SAS token?

A shared access signature is a signed URL that grants access to Azure Storage data. Its creator chooses the scope, permissions and expiry, so an over-scoped, long-lived SAS works like a permanent password in a link.

How long was the Microsoft SAS token exposed?

From 20 July 2020, when it was first committed to GitHub, until Microsoft revoked it on 24 June 2023, according to Wiz.

Toyota T-Connect Key Exposure 2022 · Microsoft Storm-0558 Signing Key Breach · Secrets Management Guide · Cloud PAM and CIEM Guide · AI Supply Chain and AI-BOM Guide

How NHI Mgmt Group can help

Signed URLs, SAS tokens and presigned links rarely appear in credential inventories. We help teams find them, set sharing standards and build detection that is triaged by people who understand the risk. See our NHI and AI agent security training.

References

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Written and reviewed by Lalit Choda, NHI Mgmt Group. Last updated 29 September 2026.
Based on the public sources listed under References. Details may change as investigations continue.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org