logo

Hackers Can Abuse Entra Agent ID Administrator Role to Hijack Service Principals

ID: 99c91eea-7daf-502d-a56f-83c0ec8d8aaf

STIX ID: report--99c91eea-7daf-502d-a56f-83c0ec8d8aaf

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-04-25

Date Updated: 2026-04-25

Author: Abinaya

...
...

A scope-overreach vulnerability in Microsoft Entra Agent Identity Platform allowed the Agent ID Administrator role to modify ownership of arbitrary service principals, enabling attackers to create credentials for high-privilege applications and potentially achieve full tenant compromise; Microsoft deployed a patch in April 2026 and the report includes detection scripts and guidance to treat privileged service principals as critical assets.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.