Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

Chinese Silk Typhoon hacker extradited to US for coronavirus research cyber attack

Turning CO2 from municipal waste into useful consumer products

Semiconductor innovation depends on new measurement methods and the UK can play a leading role

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » Microsoft patches Entra ID role flaw that allowed service principal takeover
Identity

Microsoft patches Entra ID role flaw that allowed service principal takeover

By April 28, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

Ravi LakshmananApril 28, 2026Vulnerability/Identity Management

Administrative roles for artificial intelligence (AI) agents within Microsoft Entra ID could potentially enable privilege escalation and identity takeover attacks, according to new findings from Silverfort.

Agent Identity Administrator is a privileged built-in role introduced by Microsoft as part of the Agent Identity Platform to handle all aspects of identity lifecycle operations for AI agents in your tenant. The platform allows AI agents to securely authenticate to access needed resources and discover other agents.

However, a shortcoming discovered by the Identity Security Platform meant that by becoming an owner, a user assigned the Agent Identity Administrator role could take over any service principal, including service principals beyond agent-related identities, and add their own credentials to authenticate as that principal.

“This is a full-service principal takeover,” said security researcher Noah Ariel. “For tenants with highly privileged service principals, this is the privilege escalation path.”

This ownership of the service principal effectively opens the door for attackers to operate within the scope of existing permissions. If the targeted service principal has elevated permissions, especially privileged directory roles or influential graph app permissions, an attacker may be able to gain broader control over the tenant.

Following responsible disclosure on March 1, 2026, Microsoft rolled out a patch to fix the scope overrun to all cloud environments on April 9. After the fix, attempts to use the Agent Identity Administrator role to assign ownership to non-agent service principals will be blocked with a “Forbidden” error message.

Silverfort noted that this architectural issue highlights the need to examine how role scope and permissions are applied, especially when it comes to shared identity components and when new identity types are built on top of existing primitive foundations.

To mitigate the threat posed by this risk, organizations are encouraged to monitor the usage of sensitive roles, especially those related to changes in service principal ownership or credentials, track changes in service principal ownership, secure privileged service principals, and audit the creation of service principal credentials.

“Agent identity is part of a broader shift towards non-human identities that is building for the era of AI agents,” Ariel said. “When role permissions are applied on top of a shared foundation without strict scoping, access can be expanded beyond what was originally intended. In this case, the gap led to expanded access, especially when privileged service principals were involved.”

“Furthermore, overall risk is influenced by tenant posture, particularly around privileged service principals. Ownership abuse remains a well-known and influential attack vector.”


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleMicrosoft confirms active exploitation of Windows Shell CVE-2026-32202
Next Article Semiconductor innovation depends on new measurement methods and the UK can play a leading role

Related Posts

Chinese Silk Typhoon hacker extradited to US for coronavirus research cyber attack

April 28, 2026

Microsoft confirms active exploitation of Windows Shell CVE-2026-32202

April 28, 2026

Checkmarx confirms GitHub repository data posted to dark web after March 23rd attack

April 27, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Chinese Silk Typhoon hacker extradited to US for coronavirus research cyber attack

Turning CO2 from municipal waste into useful consumer products

Semiconductor innovation depends on new measurement methods and the UK can play a leading role

Microsoft patches Entra ID role flaw that allowed service principal takeover

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.