logo

Investigating suspicious AI workflows in Microsoft Entra Agent ID: Autonomous agents

ID: 183f8985-a115-599a-b5ab-629b45d3ed94

STIX ID: report--183f8985-a115-599a-b5ab-629b45d3ed94

Feed Name: Red Canary

Threat Score
65/100

Date Published: 2026-05-27

Date Updated: 2026-05-28

Author: Matt Graeber

...
...

**Executive summary:** This report analyzes how Microsoft Entra Agent ID identities can be abused, illustrating a case in which an autonomous agent (Agent001) added a client secret to a production agent identity blueprint—an action that breaks intended blueprint/principal/agent inheritance and can enable privilege escalation and persistent access; the document explains Agent ID concepts, provides an alert example with tenant ID, agent ID, IP and user-agent, and discusses raw logs and detection/investigation guidance for agent-originated threats.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.