Microsoft has fixed a critical vulnerability in Entra ID that allowed users with the Agent ID Administrator role to take control of arbitrary service principals and escalate their privileges across entire tenants. The discovery was made by researchers at Silverfort and revealed that the role intended for managing AI agents had overly broad privileges that allowed the seizure of service principals outside of its intended scope.
See also: Critical vulnerability in Microsoft Entra ID allows full administrative control

Agent ID Administrator is a privileged built-in role introduced by Microsoft as part of the Agent Identity to manage all aspects of the identity lifecycle of AI agents in a tenant. The platform enables AI agents to securely authenticate and access necessary resources, as well as discover other agents.
However, the vulnerability discovered by the identity security team meant that users assigned the Agent ID Administrator could take control of arbitrary service principals, including those not associated with agent identities, by becoming the owner and then adding their own credentials to identify as that principal.
Technical details of the Entra ID attack
As security researcher Noa Ariel, “This is complete service principal takeover. In tenants where there are high-privilege service principals, it becomes a privilege escalation path.” Owning a service principal essentially opens the door for an attacker to operate within the scope of their existing privileges.
The exploitation process involved four critical steps. First, the attacker used the Microsoft Graph API or Azure CLI to identify highly privileged service principals, specifically targeting those with high-impact privileges such as RoleManagement.ReadWrite.Directory. Second, they exploited the overly broad role privileges to add themselves as the owner of a service principal that was not associated with agents.
See also: Microsoft fixes critical flaw in Entra ID

Then, after becoming the owner, the attacker would perform credential injection by adding a new password or certificate to the compromised service principal. Finally, they would impersonate that service principal, gaining access to its privileges and potentially escalating to a full tenant compromise if the service principal held high directory roles or high-impact Graph API.
Microsoft responded quickly to the report made on March 1, 2026 , and deployed a fix to all cloud environments on April 9. After the fix, any attempt to assign ownership to non-agent service principals using the Agent ID Administrator role is now blocked, resulting in a “ Forbidden ” error message.
Broader implications for Entra ID security
This vulnerability is part of a broader pattern of security issues in Entra ID. Recently, Microsoft addressed CVE-2025-55241, a critical vulnerability that allowed attackers to gain full administrative control of tenants by exploiting an old authentication mechanism in the Azure AD Graph API. Additionally, researchers identified a privilege escalation technique that allowed gaining Global Administrator by seizing the Exchange Online service principal.
Silverfort noted that the architectural problem highlights the need to validate how roles are scoped and permissions are enforced, particularly when it comes to shared identities and new identity types that build on the foundation of existing primitives. As Ariel, “Agent identities are part of a broader shift toward non-human identities, built for the era of AI agents.”
See also: Learn all about Microsoft's Agent Governance Toolkit

To mitigate the threat posed by this risk, organizations are advised to monitor the use of sensitive roles, particularly those related to service principal ownership or credential changes, monitor service principal ownership changes, secure privileged service principals, and control the creation of credentials on service principals.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
