Hackers Can Abuse Agent ID Administrator Role to Hijack Service Principals
ID: e95ad5eb-8c49-5d33-aede-9a3ae567b970
STIX ID: report--e95ad5eb-8c49-5d33-aede-9a3ae567b970
Feed Name: Cyber Press
Microsoft Entra ID's newly introduced Agent Identity Platform had a privilege-escalation flaw permitting Agent ID Administrator role holders to add themselves as owners of arbitrary service principals, generate credentials, and authenticate as those principals; Microsoft patched the issue by April 9, 2026 after responsible disclosure, and organizations are advised to monitor privileged role assignments, audit service principal ownership changes, and treat service principals as critical infrastructure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
