If you need an OAuth2 token from Azure Managed Identity , you do not use a webhook. You use the standard IMDS endpoint like this:
. In the context of a "webhook URL," this typically refers to a Server-Side Request Forgery (SSRF)
/metadata/identity/oauth2/token is more dangerous than the older /latest/meta-data/ because: