logo

Microsoft Entra Agent ID Flaw Enabled Tenant Takeover via Privilege Escalation

ID: 0283b629-d921-5a06-bc39-2e2a2297afdf

STIX ID: report--0283b629-d921-5a06-bc39-2e2a2297afdf

Feed Name: HackRead

Threat Score
75/100

Date Published: 2026-04-26

Date Updated: 2026-05-05

Author: Deeba Ahmed

...
...

Silverfort researchers found a scope misconfiguration in Microsoft Entra Agent ID: the Agent ID Administrator role could add itself as owner to non-agent Service Principals, inject credentials (passwords/certificates), and authenticate as those applications, enabling full tenant takeover. A demo showed a Global Administrator account hijack. The flaw was reported in late Feb/early Mar 2026, confirmed by Microsoft, and a fix was deployed by 9 April 2026; organizations are advised to audit ownership changes and new secrets on sensitive accounts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.