Hazy Issue in Entra ID Allows Privileged Users to Become Global Admins
ID: 052b9097-0080-5cec-a8c7-92922ce76b70
STIX ID: report--052b9097-0080-5cec-a8c7-92922ce76b70
Feed Name: Dark Reading
A Black Hat presentation disclosed that Microsoft Entra ID has a weakness where privileged Application or Cloud Application Administrator roles can assign credentials to service principals and then use OAuth client credential flows to act as those applications; certain Microsoft service principals (Viva Engage, Rights Management Service, Device Registration Service) were found to have excessive capabilities, including a path to Global Administrator escalation. Microsoft rated the issues, applied mitigations to limit credential use on service principals, and advised organizations to audit Entra ID logs and application admin practices, though exploitation in the wild is unconfirmed.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
