logo

Microsoft Entra Agent ID Logs Reveal Suspicious Assistive Agent Activity

ID: adcd5d7b-c4d3-5171-8ae8-a1d5bd93dcc8

STIX ID: report--adcd5d7b-c4d3-5171-8ae8-a1d5bd93dcc8

Feed Name: cybersecurityNews.com

Threat Score
65/100

Date Published: 2026-06-09

Date Updated: 2026-06-09

Author: Tushar Subhra Dutta

...
...

This Red Canary investigation details how assistive AI agents, when granted delegated access via Microsoft Entra On Behalf Of flows, can be abused to perform malicious actions that appear to come from legitimate users. The report demonstrates detection by correlating Purview Exchange, Graph Activity, and sign-in logs, highlights key log fields (e.g., Agent.agentType, Agent.parentAppId), and publishes IoCs—IP addresses, agent/app IDs, tenant and endpoint details—plus recommendations for defenders to monitor delegated permission grants and unexpected Graph API Mail.Send activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.