Azure Data Factory runs data pipelines, and a pipeline executes as the factory's managed identity. A principal that can author and trigger a pipeline runs activities (Web, Azure Function, or a custom activity) under that identity, which turns control of a data factory into a token for whatever the factory identity is granted. Linked services also store connection secrets that can be read back.
Running a pipeline as the factory identity#
az datafactory list -g <rg> -o table
# author a pipeline with a Web activity that calls ARM or Graph as the factory MI,
# or that hits IMDS-style token endpoints, then trigger it
az datafactory pipeline create-run --factory-name <df> -g <rg> --name <pipeline>
Looting linked services#
# linked services hold connection strings and credential references
az datafactory linked-service list --factory-name <df> -g <rg>
Exploitation notes#
- The factory system-assigned identity is frequently granted Storage or Key Vault access so pipelines can read data; a Web activity calling those APIs inherits that access.
- A self-hosted integration runtime runs on a VM you may be able to reach, and holds credentials for on-prem sources.
- Pipeline runs are a quiet execution channel: they look like normal data movement, not interactive compute.
Tools#
- az cli (
az datafactory pipeline create-run,az datafactory linked-service list). - MicroBurst: enumerates data factories and linked-service secrets.