VMTech
Discuss a project

Microsoft fixes Entra ID vulnerability enabling service principal takeover

Microsoft fixes Entra ID vulnerability enabling service principal takeover

Colleagues, a cybersecurity alert: Microsoft has remediated an Entra ID vulnerability.

What was found: Silverfort reported that the Agent ID Administrator role could become owner of arbitrary service principals and add credentials.

Risk: full service-principal takeover and privilege escalation where privileged roles or broad Microsoft Graph permissions exist.

Fix: disclosed 1 March; Microsoft released a patch on 9 April — assigning owner to non‑agent SPs now returns 'Forbidden'.

Recommendations: monitor sensitive roles, track SP owner changes and audit credential creation.

Why it matters: SP ownership permits actions within the principal's privileges, so owner control is critical.

What measures have you implemented to protect your SPs?

#cybersecurity #EntraID #cloudsecurity

Open analytics
On the site 6 views
min read 1 28.04.2026
On Instagram 3 views
On Instagram 1 reach
Instagram

Microsoft fixes Entra ID vulnerability enabling service principal takeover

Open the post on Instagram ↗