logo

Microsoft Patches Entra ID Role Flaw That Enabled Service Principal Takeover

ID: 1fdd198b-39ed-5dbd-b547-3e24d957a232

STIX ID: report--1fdd198b-39ed-5dbd-b547-3e24d957a232

Feed Name: The Hacker News

Threat Score
70/100

Date Published: 2026-04-28

Date Updated: 2026-04-28

Author: [email protected] (The Hacker News)

...
...

Silverfort reported that Microsoft Entra ID's Agent ID Administrator built-in role could be abused to become owner of arbitrary service principals and add credentials, enabling full service principal takeover and potential tenant-wide privilege escalation; Microsoft released a patch on April 9, 2026 to block assigning ownership of non-agent service principals with this role. Organizations are advised to monitor sensitive role usage, audit service principal ownership and credential creation, and secure privileged service principals to mitigate the risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.