“All API Connections must be considered insecure as long as Readers can call the backend server.”

Azure API Connections let anyone with Reader access call backend services using the stored credentials. That meant Key Vault secrets, SQL rows, and Jira tokens. Microsoft rejected the report first, then fixed it within a week.