logo

Hazy Issue in Entra ID Allows Privileged Users to Become Global Admins

ID: 052b9097-0080-5cec-a8c7-92922ce76b70

STIX ID: report--052b9097-0080-5cec-a8c7-92922ce76b70

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2024-08-07

Date Updated: 2026-04-21

Author: Nate Nelson, Contributing Writer

...
...

A Black Hat presentation disclosed that Microsoft Entra ID has a weakness where privileged Application or Cloud Application Administrator roles can assign credentials to service principals and then use OAuth client credential flows to act as those applications; certain Microsoft service principals (Viva Engage, Rights Management Service, Device Registration Service) were found to have excessive capabilities, including a path to Global Administrator escalation. Microsoft rated the issues, applied mitigations to limit credential use on service principals, and advised organizations to audit Entra ID logs and application admin practices, though exploitation in the wild is unconfirmed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.