Hackers Can Abuse Entra Agent ID Administrator Role to Hijack Service Principals

A critical scope overreach vulnerability was recently identified in the Microsoft Entra Agent Identity Platform. The newly introduced Agent ID Administrator role allowed accounts to hijack arbitrary service principals and escalate privileges across the entire tenant. Microsoft has fully patched this behavior across all cloud environments as of April 2026. How the Permission Boundary Breaks […]

The post Hackers Can Abuse Entra Agent ID Administrator Role to Hijack Service Principals appeared first on Cyber Security News.

This article has been indexed from Cyber Security News

Read the original article: