logo

I SPy: Escalating to Entra ID's Global Admin with a first-party app

ID: 62a1889d-ded7-5d18-a5ca-18a4bf2486fa

STIX ID: report--62a1889d-ded7-5d18-a5ca-18a4bf2486fa

Feed Name: Datadog Security Labs

Threat Score
75/100

Date Published: 2025-07-16

Date Updated: 2026-04-27

...
...

Datadog SecurityLabs discovered and demonstrated that a privileged service principal (one assigned Application Administrator, Cloud Application Administrator, or Application.ReadWrite.All) could add credentials to the Office 365 Exchange Online service principal, authenticate as that Microsoft first-party app, and abuse Domain.ReadWrite.All to add a federated domain whose certificate enabled forging SAML tokens to sign in as any hybrid (on-premises-synced) user, including Global Administrators; the issue was reported to MSRC (Jan 2025) and mitigation was observed in Aug 2025.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.