Microsoft Entra Agent ID Flaw Enabled Tenant Takeover via Privilege Escalation
ID: 0283b629-d921-5a06-bc39-2e2a2297afdf
STIX ID: report--0283b629-d921-5a06-bc39-2e2a2297afdf
Feed Name: HackRead
Silverfort researchers found a scope misconfiguration in Microsoft Entra Agent ID: the Agent ID Administrator role could add itself as owner to non-agent Service Principals, inject credentials (passwords/certificates), and authenticate as those applications, enabling full tenant takeover. A demo showed a Global Administrator account hijack. The flaw was reported in late Feb/early Mar 2026, confirmed by Microsoft, and a fix was deployed by 9 April 2026; organizations are advised to audit ownership changes and new secrets on sensitive accounts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
