Close Menu
Best in TechnologyBest in Technology
  • News
  • Phones
  • Laptops
  • Gadgets
  • Gaming
  • AI
  • Tips
  • More
    • Web Stories
    • Global
    • Press Release

Subscribe to Updates

Get the latest tech news and updates directly to your inbox.

What's On
These 15 Amazon Spring Sale Tech Deals Are Actually Good. WWe Checked the Price History (2026)

These 15 Amazon Spring Sale Tech Deals Are Actually Good. WWe Checked the Price History (2026)

16 March 2026
Smartphone app claims to help men last longer in bed

Smartphone app claims to help men last longer in bed

16 March 2026
Step aboard NASA’s imminent moon mission and follow the crew day by day

Step aboard NASA’s imminent moon mission and follow the crew day by day

16 March 2026
Facebook X (Twitter) Instagram
Just In
  • These 15 Amazon Spring Sale Tech Deals Are Actually Good. WWe Checked the Price History (2026)
  • Smartphone app claims to help men last longer in bed
  • Step aboard NASA’s imminent moon mission and follow the crew day by day
  • MSI is planning to raise the price of its laptop and gaming gear by a huge margin
  • The hot AI video generator that got everyone talking may now take a while to arrive
  • Samsung’s wireless power bank tries to fill the magnetic charging gap on the Galaxy S26
  • Adobe to offer users free services $75 million over hard-to-cancel subscription mess
  • You will soon be able to talk extensively about your Garmin health data with an AI
Facebook X (Twitter) Instagram Pinterest Vimeo
Best in TechnologyBest in Technology
  • News
  • Phones
  • Laptops
  • Gadgets
  • Gaming
  • AI
  • Tips
  • More
    • Web Stories
    • Global
    • Press Release
Subscribe
Best in TechnologyBest in Technology
Home » This Microsoft Entra ID Vulnerability Could Have Been Catastrophic
News

This Microsoft Entra ID Vulnerability Could Have Been Catastrophic

News RoomBy News Room18 September 20253 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
This Microsoft Entra ID Vulnerability Could Have Been Catastrophic
Share
Facebook Twitter LinkedIn Pinterest Email

As businesses around the world have shifted their digital infrastructure over the last decade from self-hosted servers to the cloud, they’ve benefitted from the standardized, built-in security features of major cloud providers like Microsoft. But with so much riding on these systems, there can be potentially disastrous consequences at a massive scale if something goes wrong. Case in point: Security researcher Dirk-jan Mollema recently stumbled upon a pair of vulnerabilities in Microsoft Azure’s identity and access management platform that could have been exploited for a potentially cataclysmic takeover of all Azure customer accounts.

Known as Entra ID, the system stores each Azure cloud customer’s user identities, sign-in access controls, applications, and subscription management tools. Mollema has studied Entra ID security in depth and published multiple studies about weaknesses in the system, which was formerly known as Azure Active Directory. But while preparing to present at the Black Hat security conference in Las Vegas in July, Mollema discovered two vulnerabilities that he realized could be used to gain global administrator privileges—essentially god mode—and compromise every Entra ID directory, or what is known as a “tenant.” Mollema says that this would have exposed nearly every Entra ID tenant in the world other than, perhaps, government cloud infrastructure.

“I was just staring at my screen. I was like, ‘No, this shouldn’’t really happen,’” says Mollema, who runs the Dutch cybersecurity company Outsider Security and specializes in cloud security. “It was quite bad. As bad as it gets, I would say.”

“From my own tenants—my test tenant or even a trial tenant—you could request these tokens and you could impersonate basically anybody else in anybody else’s tenant,” Mollema adds. “That means you could modify other people’s configuration, create new and admin users in that tenant, and do anything you would like.”

Given the seriousness of the vulnerability, Mollema disclosed his findings to the Microsoft Security Response Center on July 14, the same day that he discovered the flaws. Microsoft started investigating the findings that day and issued a fix globally on July 17. The company confirmed to Mollema that the issue was fixed by July 23 and implemented extra measures in August. Microsoft issued a CVE for the vulnerability on September 4.

“We mitigated the newly identified issue quickly, and accelerated the remediation work underway to decommission this legacy protocol usage, as part of our Secure Future Initiative,” Tom Gallagher, Microsoft’s Security Response Center vice president of engineering, told WIRED in a statement. “We implemented a code change within the vulnerable validation logic, tested the fix, and applied it across our cloud ecosystem.”

Gallagher says that Microsoft found “no evidence of abuse” of the vulnerability during its investigation.

Both vulnerabilities relate to legacy systems still functioning within Entra ID. The first involves a type of Azure authentication token Mollema discovered known as Actor Tokens that are issued by an obscure Azure mechanism called the “Access Control Service.” Actor Tokens have some special system properties that Mollema realized could be useful to an attacker when combined with another vulnerability. The other bug was a major flaw in a historic Azure Active Directory application programming interface known as “Graph” that was used to facilitate access to data stored in Microsoft 365. Microsoft is in the process of retiring Azure Active Directory Graph and transitioning users to its successor, Microsoft Graph, which is designed for Entra ID. The flaw was related to a failure by Azure AD Graph to properly validate which Azure tenant was making an access request, which could be manipulated so the API would accept an Actor Token from a different tenant that should have been rejected.

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleChina Turns Legacy Chips Into a Trade Weapon
Next Article Cover Reveal – The Outer Worlds 2

Related Articles

These 15 Amazon Spring Sale Tech Deals Are Actually Good. WWe Checked the Price History (2026)
News

These 15 Amazon Spring Sale Tech Deals Are Actually Good. WWe Checked the Price History (2026)

16 March 2026
Smartphone app claims to help men last longer in bed
News

Smartphone app claims to help men last longer in bed

16 March 2026
Step aboard NASA’s imminent moon mission and follow the crew day by day
News

Step aboard NASA’s imminent moon mission and follow the crew day by day

16 March 2026
MSI is planning to raise the price of its laptop and gaming gear by a huge margin
News

MSI is planning to raise the price of its laptop and gaming gear by a huge margin

16 March 2026
The hot AI video generator that got everyone talking may now take a while to arrive
News

The hot AI video generator that got everyone talking may now take a while to arrive

16 March 2026
Samsung’s wireless power bank tries to fill the magnetic charging gap on the Galaxy S26
News

Samsung’s wireless power bank tries to fill the magnetic charging gap on the Galaxy S26

15 March 2026
Demo
Top Articles
5 laptops to buy instead of the M4 MacBook Pro

5 laptops to buy instead of the M4 MacBook Pro

17 November 2024128 Views
ChatGPT o1 vs. o1-mini vs. 4o: Which should you use?

ChatGPT o1 vs. o1-mini vs. 4o: Which should you use?

15 December 2024111 Views
Costco partners with Electric Era to bring back EV charging in the U.S.

Costco partners with Electric Era to bring back EV charging in the U.S.

28 October 2024100 Views

Subscribe to Updates

Get the latest tech news and updates directly to your inbox.

Latest News
Samsung’s wireless power bank tries to fill the magnetic charging gap on the Galaxy S26 News

Samsung’s wireless power bank tries to fill the magnetic charging gap on the Galaxy S26

News Room15 March 2026
Adobe to offer users free services  million over hard-to-cancel subscription mess News

Adobe to offer users free services $75 million over hard-to-cancel subscription mess

News Room15 March 2026
You will soon be able to talk extensively about your Garmin health data with an AI News

You will soon be able to talk extensively about your Garmin health data with an AI

News Room15 March 2026
Most Popular
The Spectacular Burnout of a Solar Panel Salesman

The Spectacular Burnout of a Solar Panel Salesman

13 January 2025137 Views
5 laptops to buy instead of the M4 MacBook Pro

5 laptops to buy instead of the M4 MacBook Pro

17 November 2024128 Views
ChatGPT o1 vs. o1-mini vs. 4o: Which should you use?

ChatGPT o1 vs. o1-mini vs. 4o: Which should you use?

15 December 2024111 Views
Our Picks
MSI is planning to raise the price of its laptop and gaming gear by a huge margin

MSI is planning to raise the price of its laptop and gaming gear by a huge margin

16 March 2026
The hot AI video generator that got everyone talking may now take a while to arrive

The hot AI video generator that got everyone talking may now take a while to arrive

16 March 2026
Samsung’s wireless power bank tries to fill the magnetic charging gap on the Galaxy S26

Samsung’s wireless power bank tries to fill the magnetic charging gap on the Galaxy S26

15 March 2026

Subscribe to Updates

Get the latest tech news and updates directly to your inbox.

Facebook X (Twitter) Instagram Pinterest
  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact Us
© 2026 Best in Technology. All Rights Reserved.

Type above and press Enter to search. Press Esc to cancel.