services / Azure / DNS TLSA record set
A TLSA (DANE) record set in an Azure public DNS zone. TLSA records publish which TLS certificate/public-key is trusted for a service name on the domain.
Public-facing authoritative DNS for a single domain function; write/delete affects which TLS certificates are accepted for the domain's services.
Microsoft.Network/dnszones/TLSA/delete
Deleting the TLSA record set removes a public DNS network component and the DANE certificate-pinning defense, weakening TLS trust enforcement and enabling certificate substitution.
Risks
Scope: HIGH
This privilege may grant access to sensitive data from a single organizational function, or allow interruption of a service supporting a single organizational function.
Links
Contributed by P0 Security
© 2023–present P0 Security and contributors to the IAM Privilege Catalog