All Topics
All Topics
Technology
Technology
Design
Design
Programming
Programming
Science
Science
News
News
Gaming
Gaming
Entertainment
Entertainment
Business
Business
Finance
Finance
Sports
Sports
Health
Health
Food
Food
Travel
Travel
Art
Art
Music
Music
Books
Books
Education
Education
Politics
Politics
Personal
Personal
No algorithm. No AI slop. No ads. Just RSS. Pro-human. Indie writers. Real journalism. Open web. Chronological. Hand toasted.

Critical Entra ID Vulnerability Allowed Global Admin Access Across All Microsoft Tenants

By

colinprince

8mo ago· 17 min readenInsight

Summary

A security researcher discovered a critical vulnerability in Microsoft's Entra ID (formerly Azure AD) that could have allowed complete compromise of every Entra ID tenant worldwide. The vulnerability involved undocumented "Actor tokens" used for Microsoft's backend service-to-service communication and a flaw in the legacy Azure AD Graph API that failed to properly validate tenant origins, enabling cross-tenant access and potential global admin privileges.

Key quotes

· 4 pulled
This vulnerability could have allowed me to compromise every Entra ID tenant in the world
complete access to your tenant
undocumented impersonation tokens that Microsoft uses in their backend for service-to-service (S2S) communication, called 'Actor tokens'
critical vulnerability in the (legacy) Azure AD Graph API that did not properly validate the originating tenant
Snippet from the RSS feed
While preparing for my Black Hat and DEF CON talks in July of this year, I found the most impactful Entra ID vulnerability that I will probably ever find. One that could have allowed me to compromise every Entra ID tenant in the world (except probably tho

You might also wanna read