Microsoft fixes Entra ID flaw enabling privilege escalation
ID: 3ed798f9-8ba4-5f39-835e-559dc42f6c6c
STIX ID: report--3ed798f9-8ba4-5f39-835e-559dc42f6c6c
Feed Name: Security Affairs
Threat Score
Microsoft fixed a Microsoft Entra ID privilege-escalation flaw in the Agent ID Administrator role that allowed accounts with only that role to take over arbitrary service principals by assigning ownership and adding credentials, enabling full service principal compromise and potential directory-level escalation. Researchers demonstrated a PoC; Microsoft confirmed the behavior, deployed a fix that restricts the role to agent-related objects, and rolled out the patch in April 2026.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
