logo

Hackers Can Abuse Agent ID Administrator Role to Hijack Service Principals

ID: e95ad5eb-8c49-5d33-aede-9a3ae567b970

STIX ID: report--e95ad5eb-8c49-5d33-aede-9a3ae567b970

Feed Name: Cyber Press

Threat Score
70/100

Date Published: 2026-04-24

Date Updated: 2026-05-05

Author: AnuPriya

...
...

Microsoft Entra ID's newly introduced Agent Identity Platform had a privilege-escalation flaw permitting Agent ID Administrator role holders to add themselves as owners of arbitrary service principals, generate credentials, and authenticate as those principals; Microsoft patched the issue by April 9, 2026 after responsible disclosure, and organizations are advised to monitor privileged role assignments, audit service principal ownership changes, and treat service principals as critical infrastructure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.