logo

Attackers Exploit Microsoft Entra Billing Role Exploit Enables Privilege Escalation in Organizations

ID: 3de87e45-5140-5ea5-a71c-f9fbf5c402be

STIX ID: report--3de87e45-5140-5ea5-a71c-f9fbf5c402be

Feed Name: Cyber Press

Threat Score
70/100

Date Published: 2025-05-30

Date Updated: 2026-04-19

Author: Mandvi

...
...

A privilege-escalation vulnerability involving Microsoft Entra’s Billing Administrator role allows attackers who compromise billing-role accounts (commonly via social engineering or credential theft) to reassign directory roles — potentially achieving Global Administrator — and thus gain broad control over identity, application, and data resources; Microsoft has acknowledged the risk and advised reviewing and restricting Billing Administrator assignments, auditing Entra ID permissions, and monitoring for anomalous role changes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.