datadog-security-labs · Crawled Jul 18, 2026

Entra Agent ID: Inside a cross-tenant agent compromise

1 IoCs
Read original article ↗

AI Summary

This article demonstrates a cross-tenant compromise scenario involving Entra agent identities, where an attacker compromises a privileged agent blueprint in one tenant and leverages it to gain unauthorized access to agent identities in another tenant. The attacker adds a credential to a third-party blueprint called 'People Team Agents' and uses it to authenticate as a high-privilege agent, 'Temporary Access Agent', in a subsidiary tenant. This agent has permissions to read user details and reset passwords via Microsoft Graph, which the attacker abuses to set a temporary access pass (TAP) for a Global Administrator account, achieving full compromise of the subsidiary tenant. The attack highlights the risks of trusting third-party agent blueprints with broad permissions across multiple tenants.

AI-extracted · verify before operational use

Indicators of Compromise 1 extracted

Type Value Detail
SHA-256 f6c2a2c0e0fa40e2b60fa3a28b50adb3 Details →