{"id":237664,"date":"2026-04-28T02:37:00","date_gmt":"2026-04-28T06:37:00","guid":{"rendered":"https:\/\/news-you-need.com\/index.php\/2026\/04\/28\/microsoft-patches-entra-id-role-flaw-that-enabled-service-principal-takeover\/"},"modified":"2026-04-30T20:20:11","modified_gmt":"2026-05-01T00:20:11","slug":"microsoft-patches-entra-id-role-flaw-that-enabled-service-principal-takeover","status":"publish","type":"post","link":"https:\/\/news-you-need.com\/index.php\/2026\/04\/28\/microsoft-patches-entra-id-role-flaw-that-enabled-service-principal-takeover\/","title":{"rendered":"Microsoft Patches Entra ID Role Flaw That Enabled Service Principal Takeover"},"content":{"rendered":"<p><a href=\"https:\/\/thehackernews.com\/2026\/04\/microsoft-patches-entra-id-role-flaw.html\">Microsoft Patches Entra ID Role Flaw That Enabled Service Principal Takeover<\/a><\/p>\n<p><a href=\"https:\/\/thehackernews.com\/2026\/04\/microsoft-patches-entra-id-role-flaw.html\">https:\/\/thehackernews.com\/2026\/04\/microsoft-patches-entra-id-role-flaw.html<\/a><\/p>\n<p>Publish Date: <a href=\"publish_date]\">2026-04-28 02:37:00<\/a><\/p>\n<p>Source Domain: <a href=\"thehackernews.com\">thehackernews.com<\/a><\/p>\n<p><span class=\"p-author\">\ue804<span class=\"author\">Ravie Lakshmanan<\/span>\ue802<span class=\"author\">Apr 28, 2026<\/span><\/span><span class=\"p-tags\">Vulnerability \/ Identity Management<\/span><\/p>\n<p>An administrative role meant for artificial intelligence (AI) agents within Microsoft Entra ID could enable privilege escalation and identity takeover attacks, according to new findings from Silverfort.<\/p>\n<p>Agent ID Administrator is a privileged built-in role introduced by Microsoft as part of its agent identity platform to handle all aspects of an AI agent&#8217;s identity lifecycle operations in a tenant. The platform enables AI agents to authenticate securely and access necessary resources, as well as discover other agents.<\/p>\n<p>However, the shortcoming discovered by the identity security platform meant that users assigned the Agent ID Administrator role could take over arbitrary service principals, including those beyond agent-related identities, by becoming an owner and then add their own credentials to authenticate as that principal.<\/p>\n<p>&#8220;That&#8217;s full service principal takeover,&#8221; security researcher Noa Ariel said. &#8220;In tenants where high-privileged service principals exist, it becomes a privilege escalation path.&#8221;<\/p>\n<p><img decoding=\"async\" alt=\"\" border=\"0\" data-original-height=\"433\" data-original-width=\"1024\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiWveFhhMQcTBkaG4hCYtXTMOCBC2qi3l0SWAP8WbTO3ocDNHG_9crspjYhrKXTlE00tC1ZBNsrlax1mqwBtg5j3lYS4xD80DX2woqHdsnF0EC56kSF1Tv4rioBESstJ9tXLpd5owzSLQFtVwjyaJGD8PmM_FE6LW4aInJUL5it-jgiYczaqFL0-nmIPWGY\/s1600\/flow.jpg\"\/><\/p>\n<p>This ownership of a service principal effectively opens the door to an attacker to operate within the scope of its existing permissions. If the targeted service principal holds elevated permissions \u2013 particularly privileged directory roles and high-impact Graph app permissions \u2013 it can give an attacker broader control over the tenant.<\/p>\n<p><iframe loading=\"lazy\" title=\"Agent ID Administrator takes over a privileged non-agent service principal\" width=\"640\" height=\"360\" src=\"https:\/\/www.youtube.com\/embed\/DK3Ru2OoNEM?feature=oembed\" frameborder=\"0\" allow=\"accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share\" referrerpolicy=\"strict-origin-when-cross-origin\" allowfullscreen><\/iframe><\/p>\n<p>Following responsible disclosure on March 1, 2026, Microsoft rolled out a patch across all cloud environments to remediate the scope overreach on April 9. Following the fix, any attempt to assign ownership over non-agent service principals using the Agent ID Administrator role is now blocked, and leads to a &#8220;Forbidden&#8221; error message being displayed.<\/p>\n<p>Silverfort noted that the architectural issue highlights the need for validating how roles are scoped and permissions are applied, especially when it comes&#8230;<\/p>\n<p><a href=\"https:\/\/thehackernews.com\/2026\/04\/microsoft-patches-entra-id-role-flaw.html\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Microsoft Patches Entra ID Role Flaw That Enabled Service Principal Takeover https:\/\/thehackernews.com\/2026\/04\/microsoft-patches-entra-id-role-flaw.html Publish Date: 2026-04-28&#8230;<\/p>\n","protected":false},"author":1,"featured_media":237665,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEg4YomH2AGnUSAePfyyvEMXCbULukirvclzEJ6gnsm30Y2PApuarWfCLpKrBng3qYhhINWPwn99rVtdqKcEtbnVR9jkXkpBY-vDByDzMmZgLPPPrqyodmgqBCfR3ojF1tbyaFHQxIdr8voZgDugagnBymAchRR99uUm_0btEdWYeir8B6njw6Q1lPTcugcB\/s1600\/azure.jpg","fifu_image_alt":"","footnotes":""},"categories":[15],"tags":[26,20,27],"class_list":["post-237664","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-ai","tag-artificial-intelligence","tag-vulnerability"],"_links":{"self":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/237664"}],"collection":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/comments?post=237664"}],"version-history":[{"count":1,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/237664\/revisions"}],"predecessor-version":[{"id":237666,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/237664\/revisions\/237666"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/media\/237665"}],"wp:attachment":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/media?parent=237664"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/categories?post=237664"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/tags?post=237664"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}