I SPy: Escalating to Entra ID's Global Admin with a first-party app
ID: 62a1889d-ded7-5d18-a5ca-18a4bf2486fa
STIX ID: report--62a1889d-ded7-5d18-a5ca-18a4bf2486fa
Feed Name: Datadog Security Labs
Datadog SecurityLabs discovered and demonstrated that a privileged service principal (one assigned Application Administrator, Cloud Application Administrator, or Application.ReadWrite.All) could add credentials to the Office 365 Exchange Online service principal, authenticate as that Microsoft first-party app, and abuse Domain.ReadWrite.All to add a federated domain whose certificate enabled forging SAML tokens to sign in as any hybrid (on-premises-synced) user, including Global Administrators; the issue was reported to MSRC (Jan 2025) and mitigation was observed in Aug 2025.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
