Hackers Exploit Agent ID Administrator Role to Hijack Service Principals
ID: 9b50f632-050b-56e2-9a2f-907d61d078b1
STIX ID: report--9b50f632-050b-56e2-9a2f-907d61d078b1
Feed Name: GBHackers
A critical scoping vulnerability in Microsoft Entra ID’s Agent Identity Platform allowed accounts with only the Agent ID Administrator role to take ownership of arbitrary service principals, create new credentials, and authenticate as those principals — effectively enabling severe privilege escalation across tenants. SilverFort researchers disclosed the flaw, Microsoft patched it by April 9, 2026, and organizations are advised to monitor role usage, audit privileged service principals, and alert on unexpected ownership or credential changes.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
