Microsoft Entra Agent ID Logs Expose Suspicious Assistive Agent Activity
ID: 5eff630f-5bca-5f65-ae1c-94809e652bd0
STIX ID: report--5eff630f-5bca-5f65-ae1c-94809e652bd0
Feed Name: GBHackers
Threat Score
This report describes a case where an assistive agent using the OAuth On-Behalf-Of (OBO) flow sent email as a user; investigators correlated Exchange/Purview, Microsoft Graph activity, and Azure AD non-interactive sign-in logs to identify the agent blueprint, originating IP, user-agent, and delegated Mail scopes, and it provides detection and hunting guidance (log pivots, relevant agent fields, and monitoring/least-privilege recommendations) to mitigate agent-facilitated abuse.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
