Microsoft Patches Entra ID Agent Administrator Role Flaw: New AI-Agent-Focused Role Enabled Full Tenant Takeover via Service Principal Credential Injection
Silverfort discovered that Microsoft's new Agent ID Administrator built-in role — introduced for managing AI agent identity lifecycle — could take over arbitrary service principals beyond agent-related identities by adding attacker-controlled credentials. An attacker with this role could enumerate high-privilege service principals via Graph API, claim ownership of non-agent principals, inject credentials, then authenticate as those principals with their elevated permissions. Microsoft patched across all cloud environments on April 9 after responsible disclosure on March 1; about 99% of business networks have at least one privileged service principal, and over half of companies studied already use agent identities.
↳ Follow the thread