One mis-scoped Entra Agent ID Administrator role let attackers seize any service principal and, in some setups, gain tenant-wide access. The flaw lived in Microsoft's Entra Agent Identity Platform, a preview feature that gives AI agents identities using blueprints, agent identities and agent users. Researchers at Silverfort showed the role could be used to reassign ownership of any service principal, then generate credentials and authenticate as that application. Microsoft patched the behavior across all cloud environments in April 2026, and administrators are urged to hunt for privileged service principals and secure them.
How the scope gap formed Microsoft built the Agent Identity Platform as a way to give non-human AI agents managed identities. In preview, it layers agent identities on top of existing application and service-principal primitives in Entra. To manage those agent objects, Microsoft introduced an Agent ID Administrator role that, by design, should only touch agent-related resources. But researchers at Silverfort discovered a mismatch between the intended scope of that role and how Entra enforces ownership and privilege. Because agent identities ultimately map to the same underlying service-principal and application objects used across the directory, some agent-management actions could be applied to ordinary service principals as well. Put simply: a permission that should have been limited to agent objects could be used to update owner fields on any service principal in the tenant. Once ownership changed, the new owner could create credentials for the targeted service principal and sign in as that application. Attack flow and why it matters Silverfort mapped the chain an attacker could follow. An account granted the Agent ID Administrator role can set itself as the owner of a high-privilege service principal. After it becomes owner, the account can generate new credentials for the principal and authenticate as that application. If the seized service principal already has elevated directory roles or broad Graph API permissions, the attacker gains a direct route to compromise the tenant. Attackers leveraging the weakness would naturally aim for the most powerful non-human identities in a network. Those identities often hold persistent tokens and automation rights that are hard to detect and hard to revoke without breaking services. Who is at risk The issue affects tenants using the Entra Agent Identity Platform while also assigning the Agent ID Administrator role. Because the platform is a preview feature, organizations enrolled in previews and those testing agent workflows are particularly exposed. The risk concentrates where service principals already hold admin-level directory roles or high-impact Graph API permissions. Service principals are commonly used to run automation, CI/CD pipelines, cloud services and connectors. When those principals also carry directory roles, they become attractive targets — an attacker who can impersonate a service principal can move laterally, change configurations and create persistent access paths. This incident highlights a broader risk: preview features that layer AI agent identities onto legacy identity primitives can leak privileges. Permissions intended for new, agent-specific objects may still affect underlying service-principal records, so organizations should treat agent-identity previews as high-risk and limit who can assign the Agent ID Administrator role. Detection and remediation steps offered Microsoft addressed the issue and deployed a fix across all cloud environments in April 2026, according to the advisory. Silverfort noted it will also correct a discrepancy in the Entra "privileged" indicator that contributed to the scoping confusion. Until tenants confirm the patch in their environments, the primary defensive action is to locate service principals that hold privileged directory roles and secure them. Silverfort recommended administrators proactively identify those principals and take steps to harden or remove unnecessary privileges. To assist that hunt, administrators can query Microsoft Graph for role definitions flagged as privileged and then list role assignments that map back to service principals. Silverfort demonstrated doing the discovery using Azure CLI to call Microsoft Graph and filtering results with jq so teams can generate an inventory of principals.Related Articles
- Are $100+ Smart Bird Feeders Worth It?
- Apple’s leadership shake-up spotlights product-first CEOs as lululemon names Heidi O’Neill
- ChatGPT hits 900 million weekly users as restaurants plug in ordering
Microsoft patched the Agent ID Administrator behavior across all cloud environments in April 2026. Administrators should confirm the fix in their tenants and immediately hunt for service principals holding elevated directory roles to remove or harden unnecessary privileges.
This article was created with AI assistance.