logo

Microsoft Entra Billing Roles Vulnerability Could Enable Privilege Escalation in Organizations

ID: e52b4e3c-8c9f-5303-a010-579f732e205d

STIX ID: report--e52b4e3c-8c9f-5303-a010-579f732e205d

Feed Name: Cyber Press

Threat Score
70/100

Date Published: 2025-05-30

Date Updated: 2026-04-19

Author: Mayura

...
...

A billing-permissions issue in Microsoft Azure / Entra ID allows guest users who hold Enterprise Agreement or Microsoft Customer Agreement billing roles to create and transfer subscriptions into tenants where they are guests, automatically gaining Owner-level access. This access enables enumeration of privileged accounts, modification or disabling of policies, creation of user-managed identities (potential persistent backdoors), and registration of Azure-joined devices; Microsoft characterizes the behavior as expected and published subscription policy controls, while BeyondTrust recommends auditing guests and enabling restrictive subscription policies.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.