Skip to content

Lab 02 — Azure Functions Security Assessment

Property Value
Lab Name Azure Functions Security Assessment
Module Module 07 — Serverless Security
Lab Number Lab 02
Difficulty Intermediate
Estimated Time 90–120 Minutes
Cloud Provider Microsoft Azure
Environment Azure Functions
Prerequisites Complete Lessons 01–09
Tools Used Azure Portal, Azure CLI, Microsoft Entra ID, Azure Monitor, Azure Activity Logs, Azure Key Vault, Azure Storage Explorer

CloudNova Technologies has been contracted by MedSecure Global to perform an enterprise security assessment of its Azure Functions environment.

The organization operates serverless applications supporting healthcare automation, patient scheduling, financial processing, AI-powered analytics, and enterprise APIs. These workloads integrate with Microsoft Entra ID, Azure Storage, Azure Key Vault, Event Grid, and Azure Monitor.

Executive leadership wants assurance that Azure Functions follow enterprise security standards, implement least privilege, securely manage secrets, and provide sufficient visibility for the Security Operations Centre (SOC).

You have been assigned as the Lead Cloud Penetration Tester responsible for assessing Azure Functions security and preparing a professional consulting report.


By completing this lab you will learn how to:

  • Assess Azure Functions security.
  • Review Managed Identities.
  • Evaluate Microsoft Entra ID integration.
  • Assess Azure Storage security.
  • Review networking and authentication.
  • Validate Azure Key Vault integration.
  • Evaluate monitoring and logging.
  • Produce an enterprise security assessment.

During this engagement you will assess:

  • Azure Functions
  • Managed Identities
  • Microsoft Entra ID
  • Azure Storage
  • Azure Key Vault
  • Azure Event Grid
  • Azure Service Bus
  • Azure Monitor
  • Azure Activity Logs

Users
Azure API Management
Azure Functions
Managed Identity
Microsoft Entra ID
Azure Services
├── Azure Storage
├── Azure SQL
├── Cosmos DB
├── Azure Key Vault
├── Event Grid
├── Service Bus
Azure Monitor
Microsoft Sentinel
Security Operations Centre (SOC)

Review:

  • Function Apps
  • Runtime versions
  • Hosting plans
  • Deployment regions
  • Business owners
  • Function triggers

Expected Outcome

Create a complete inventory of Azure Functions deployed within the Azure subscription.


Review:

  • System-assigned Managed Identities
  • User-assigned Managed Identities
  • Azure RBAC assignments
  • Resource permissions
  • Identity ownership

Identify:

  • Excessive permissions
  • Contributor/Owner assignments
  • Unused identities
  • Cross-subscription access

Expected Outcome

Validate that Managed Identities follow the Principle of Least Privilege.


Task 03 — Review Microsoft Entra ID Integration

Section titled “Task 03 — Review Microsoft Entra ID Integration”

Assess:

  • Authentication configuration
  • Enterprise Applications
  • Service Principals
  • Conditional Access Policies
  • Multi-Factor Authentication (MFA)
  • OAuth permissions

Verify:

  • Secure authentication
  • Restricted administrative access
  • Identity governance

Expected Outcome

Ensure Azure Functions integrate securely with Microsoft Entra ID.


Review:

  • Storage Accounts
  • Blob Containers
  • Queue Storage
  • Azure Files
  • Table Storage
  • Storage firewall configuration

Validate:

  • Private access
  • Encryption at rest
  • Public access restrictions
  • Access control lists (ACLs)

Expected Outcome

Identify storage-related security weaknesses affecting Azure Functions.


Assess:

  • Virtual Network (VNet) Integration
  • Private Endpoints
  • Network Security Groups (NSGs)
  • Firewall rules
  • Outbound connectivity
  • Public endpoint exposure

Expected Outcome

Determine whether Azure Functions follow enterprise networking standards.


Review:

  • Secret storage
  • Certificates
  • Encryption keys
  • Access policies
  • Managed Identity access
  • Secret rotation

Verify:

  • Least privilege access
  • Encryption
  • Secure retrieval of secrets

Expected Outcome

Confirm that sensitive credentials are securely stored and managed.


Assess:

  • HTTP Triggers
  • Event Grid
  • Azure Service Bus
  • Azure Storage Triggers
  • Timer Triggers
  • Cosmos DB Triggers

Validate:

  • Authentication
  • Authorization
  • Trigger permissions
  • Input validation

Expected Outcome

Ensure only trusted event sources can invoke production functions.


Review:

  • Azure Monitor
  • Application Insights
  • Azure Activity Logs
  • Diagnostic Logs
  • Microsoft Defender for Cloud
  • Microsoft Sentinel

Validate:

  • Log collection
  • Alerting
  • SIEM integration
  • Security telemetry
  • Log retention

Expected Outcome

Determine whether the SOC has sufficient visibility into Azure Functions activity.


Classify findings as:

  • Critical
  • High
  • Medium
  • Low
  • Informational

Prioritize remediation according to business impact and exploitability.


Task 10 — Produce Executive Assessment Report

Section titled “Task 10 — Produce Executive Assessment Report”

Prepare:

  • Executive Summary
  • Azure Functions Architecture Review
  • Managed Identity Assessment
  • Microsoft Entra ID Review
  • Azure Storage Assessment
  • Azure Key Vault Assessment
  • Monitoring Assessment
  • Risk Register
  • Security Scorecard
  • Remediation Roadmap

At the conclusion of this lab you should produce:

  • Azure Functions Security Assessment Report
  • Azure Functions Inventory
  • Managed Identity Review
  • Microsoft Entra ID Assessment
  • Azure Storage Security Review
  • Azure Key Vault Assessment
  • Monitoring Assessment
  • Risk Register
  • Executive Summary
  • Evidence Screenshots

You have successfully completed this lab when you can:

  • Assess Azure Functions using an enterprise methodology.
  • Review Managed Identities and Microsoft Entra ID security.
  • Evaluate Azure Storage and Azure Key Vault security.
  • Assess networking, event sources, and monitoring.
  • Prioritize findings based on business impact.
  • Produce professional consulting documentation.

After completing this lab you will be able to perform responsibilities commonly expected of:

  • Cloud Penetration Tester
  • Azure Security Consultant
  • Serverless Security Engineer
  • Cloud Security Engineer
  • DevSecOps Security Engineer
  • Enterprise Security Consultant

In this lab, you performed a comprehensive enterprise security assessment of Azure Functions using the GoHackersCloud Enterprise Serverless Security Assessment Framework.

You reviewed Managed Identities, Microsoft Entra ID integration, Azure Storage, Azure Key Vault, networking, event sources, monitoring, and logging before documenting technical findings and business risks in a professional consulting report.


➡️ Lab 03 — Google Cloud Functions Security Assessment

In the next lab, you will assess Google Cloud Functions by reviewing Service Accounts, Google Cloud IAM, Eventarc, Pub/Sub, Cloud Storage, Secret Manager, networking, monitoring, and governance using the GoHackersCloud Enterprise Serverless Security Assessment Framework.