{"id":12394,"date":"2026-04-25T10:05:04","date_gmt":"2026-04-25T10:05:04","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/04\/25\/hackers-can-abuse-entra-agent-id-administrator-role-to-hijack-service-principals\/"},"modified":"2026-04-25T10:05:04","modified_gmt":"2026-04-25T10:05:04","slug":"hackers-can-abuse-entra-agent-id-administrator-role-to-hijack-service-principals","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/04\/25\/hackers-can-abuse-entra-agent-id-administrator-role-to-hijack-service-principals\/","title":{"rendered":"Hackers Can Abuse Entra Agent ID Administrator Role to Hijack Service Principals"},"content":{"rendered":"<p>    Hackers Can Abuse Entra Agent ID Administrator Role to Hijack Service Principals<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A critical scope overreach vulnerability was recently identified in the Microsoft Entra Agent Identity Platform. The newly introduced Agent ID Administrator role allowed accounts to <a href=\"https:\/\/cybersecuritynews.com\/openclaw-0-click-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">hijack arbitrary service<\/a> principals and escalate privileges across the entire tenant.<\/p>\n<p>Microsoft has fully patched this behavior across all cloud environments as of April 2026.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-how-the-permission-boundary-breaks\"><strong>How the Permission Boundary Breaks<\/strong><\/h2>\n<p>The Microsoft Agent Identity Platform is a preview feature that provides artificial intelligence agents with identities using blueprints, agent identities, and agent users.<\/p>\n<p>To manage these non-human entities, Microsoft introduced the Agent ID Administrator role. <a href=\"https:\/\/learn.microsoft.com\/en-us\/entra\/identity\/role-based-access-control\/permissions-reference\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">According to Microsoft documentation<\/a>, this role was strictly scoped to manage only agent-related objects.<\/p>\n<figure class=\"wp-block-image size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiaReI_j-O_Q_a9O3iazU7JNpU7-zV4J3QlwyNtJ9T72Nir1Zuua-BrV0QYYon83GjQ3HVubAhfgJVMaYy5q3QOEj7IDAWqlwg8jSI0fVpWUrQZuNitlg3LWLqJHe5tgaKAk4G0hMOoFF_KtO-Ahc3mGoK7nPHW311ZkPLqZslOd-bvHyNIqxJMF4WHtmM\/s1600\/Screenshot%25202026-04-24%2520184341%2520%25281%2529.webp?ssl=1\" alt=\"A discrepancy in the Microsoft Entra \u201cprivileged\u201d indicator will be fixed(source : SilverFort)\"><figcaption class=\"wp-element-caption\">A discrepancy in the Microsoft Entra \u201cprivileged\u201d indicator will be fixed(source : SilverFort)<\/figcaption><\/figure>\n<p>However, because agent identities are built on top of standard application and service principal primitives, a critical scoping gap emerged.<\/p>\n<p>Silverfort researchers found that actions like updating agent identity owners allowed administrators to modify the ownership of any service principal in the tenant.<\/p>\n<p>A user with the <a href=\"https:\/\/cybersecuritynews.com\/microsoft-details-on-how-security-copilot-in-intune\/\" target=\"_blank\" rel=\"noreferrer noopener\">Agent ID Administrator<\/a> role could assign themselves as the owner of a completely unrelated, high-privileged service principal.<\/p>\n<p>Once ownership was established, the attacker could generate new credentials and authenticate as that targeted application.<\/p>\n<p>If the compromised service principal held elevated directory roles or high-impact Graph API permissions, this takeover primitive provided a direct path to full compromise of the environment.<\/p>\n<figure class=\"wp-block-image size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEg0FUB4KgkdhbiUdy8SSnbO_W6IWHqAaKrC93JgfuDmU_J_zUDT4p2FK_SaSibIgRc_1jNaEPO8PvV_GXG-u1fcDyB7nS4G-YgpVVwgsvFbNsxl45f5BtsAx7dr_qOafDy9GIvIM6qL1kiUm3zU5yqewbsrpabVY53sfiKVKHk9_e0VVnYH7mplLuo3FGc\/s1600\/Screenshot%25202026-04-24%2520184356%2520%25281%2529.webp?ssl=1\" alt=\"Attack Flow(Source: SilverFort)\"><figcaption class=\"wp-element-caption\"><em>Attack Flow(Source: SilverFort)<\/em><\/figcaption><\/figure>\n<p>Attackers leveraging this vulnerability would naturally target the most powerful non-human identities in a network.<\/p>\n<p><a href=\"https:\/\/www.silverfort.com\/blog\/agent-id-administrator-scope-overreach-service-principal-takeover-in-entra-id\/\" target=\"_blank\" rel=\"noreferrer noopener\">According to Silverfort research<\/a>, organizations should proactively identify service principals with admin-level directory roles and secure them appropriately.<\/p>\n<p>Administrators can utilize the Azure CLI alongside jq to query the <a href=\"https:\/\/cybersecuritynews.com\/m365pwned-red-team-gui-toolkit\/\" target=\"_blank\" rel=\"noreferrer noopener\">Microsoft Graph API<\/a> for these vulnerable configurations.<\/p>\n<p>The following script discovers service principals with privileged directory roles.<\/p>\n<p><code>BASE=\"https:\/\/graph.microsoft.com\"<br \/>roles=\"$(az rest -m GET --url \"${BASE}\/beta\/roleManagement\/directory\/roleDefinitions?$filter=isPrivileged eq true&amp;$select=id,displayName\" -o json)\"<br \/>u=\"${BASE}\/beta\/roleManagement\/directory\/roleAssignments?$expand=principal($select=id,displayName)&amp;$top=999\"<br \/>{<br \/>echo -e \"SP_NAMEtSP_IDtROLE\"<br \/>echo -e \"--------t------t----\"<br \/>while :; do<br \/>j=\"$(az rest -m GET --url \"$u\" -o json 2&gt;\/dev\/null)\" || break<br \/>jq -r --argjson roles \"$roles\" '<br \/>($roles.value | map(select(.displayName|test(\"Reader\";\"i\")|not) | {key:.id, value:.displayName}) | from_entries) as $r<br \/>| .value[]<br \/>| select(.principal.\"@odata.type\"==\"#microsoft.graph.servicePrincipal\")<br \/>| select($r[.roleDefinitionId] != null)<br \/>| [.principal.displayName, (.principal.id \/\/ .principalId), $r[.roleDefinitionId]] | @tsv<br \/>' &lt;&lt;&lt;\"$j\"<br \/>u=\"$(jq -r '.\"@odata.nextLink\"\/\/empty' &lt;&lt;&lt;\"$j\")\"<br \/>[[ -z \"$u\" ]] &amp;&amp; break<br \/>done | sort -t$'t' -k1,1<br \/>} | column -t -s $'t'<\/code><\/p>\n<p>Microsoft acknowledged the issue and deployed a fix that prevents the Agent ID Administrator role from managing the owners of non-agent service principals.<\/p>\n<figure class=\"wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio\">\n<div class=\"wp-block-embed__wrapper\">\n<div class=\"youtube-embed\" data-video_id=\"DK3Ru2OoNEM\"><iframe loading=\"lazy\" title=\"Agent ID Administrator takes over a privileged non-agent service principal\" width=\"696\" height=\"392\" src=\"https:\/\/www.youtube.com\/embed\/DK3Ru2OoNEM?start=2&amp;feature=oembed\" frameborder=\"0\" allow=\"accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share\" referrerpolicy=\"strict-origin-when-cross-origin\" allowfullscreen><\/iframe><\/div>\n<\/div>\n<\/figure>\n<p>While the immediate threat is resolved, the underlying risk of service principal ownership abuse remains a high-value attack path.<\/p>\n<p>Security teams must actively monitor their audit logs for successful events involving the addition of owners or credentials to service principals.<\/p>\n<p>Because many tenants contain at least one privileged service principal, treating these identities as critical infrastructure is essential to preventing future <a href=\"https:\/\/cybersecuritynews.com\/microsoft-defender-0-day-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">privilege escalation attacks<\/a>.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/entra-agent-id-administrator-abused\/\">Hackers Can Abuse Entra Agent ID Administrator Role to Hijack Service Principals<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Abinaya<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/entra-agent-id-administrator-abused\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Hackers Can Abuse Entra Agent ID Administrator Role to Hijack Service Principals A critical scope overreach vulnerability was recently identified in the Microsoft Entra Agent Identity Platform. The newly introduced Agent ID Administrator role allowed accounts to hijack arbitrary service principals and escalate privileges across the entire tenant. Microsoft has fully patched this behavior across [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,158],"tags":[130],"class_list":["post-12394","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-microsoft","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/12394"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=12394"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/12394\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=12394"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=12394"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=12394"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}