ExposedToTenant

Reachable/usable by any principal in the tenant/org (broad blast radius).

network NETWORK nature: derived walkable weight 2
*  ── ExposedToTenant ──▸  Tenant, Organization

Source types

*

Target types

States

ACTIVE CONDITIONAL POTENTIAL BLOCKED UNKNOWN

Derivation

naturederived

Rules that emit ExposedToTenant 14

A RAM share whose principal is the organization root (o-*) exposes the shared resource to every current and future member account in the organization - ExposedToTenant.
awsderived
Cosmos DB account with firewall restricted to 0.0.0.0 (all Azure IPs) - accessible from any Azure-hosted workload but not the open internet.
azurederived
Public-network + Allow-default firewall exposes the data plane tenant-wide (still Entra-authz).
azurederived
Allow Azure services rule (startIp=endIp=0.0.0.0) exposes the SQL server to all Azure tenants and multi-tenant services - not public internet but broad cross-tenant exposure.
azurederived
A CA-pool binding granting requester/use to allUsers/allAuthenticatedUsers exposes issuance broadly.
gcpderived
Firebase Security Rules requiring only 'request.auth != null' (authenticated but no domain/claim restriction) make the Firestore database accessible to any Firebase Auth user - including users outside the organization.
gcpderived
A bucket IAM binding granting any read role to allAuthenticatedUsers makes the bucket readable by any Google-authenticated user worldwide (not limited to the organization) - broad tenant-wide exposure including external Google accounts.
gcpderived
A key allow policy binding allUsers/allAuthenticatedUsers to a crypto role exposes it broadly.
gcpderived
A snapshot with allAuthenticatedUsers or allUsers in its IAM policy is exposed to all GCP identities (authenticated or nominally public) across all projects/organizations.
gcpderived
A secret allow policy binding allUsers/allAuthenticatedUsers to secretAccessor exposes the payload broadly.
gcpderived
An IAM binding on a Firestore database naming 'allAuthenticatedUsers' allows access to any GCP-authenticated user, exposing data tenant-wide.
gcpexplicit
A dataset ACL entry for allAuthenticatedUsers makes it readable by any Google-authenticated user - org-wide or tenant-wide exposure.
gcpexplicit
move · open · esc close