Microsoft corrected a public-by-default configuration and code flaws in a cloud automation service that may have created a cross-tenant identity risk, without any confirmed exploitation in the available material.