Campfire
Archive Tags About

One Token to rule them all - obtaining Global Admin in every Entra ID tenant via Actor tokens

Visit link →
Screenshot of One Token to rule them all - obtaining Global Admin in every Entra ID tenant via Actor tokens
While preparing for my Black Hat and DEF CON talks in July of this year, I found the most impactful Entra ID vulnerability that I will probably ever find. One that could have allowed me to compromise every Entra ID tenant in the world (except probably those in national cloud deployments). If you are an Entra ID admin reading this, yes that means complete access to your tenant. The vulnerability consisted of two components: undocumented impersonation tokens that Microsoft uses in their backend for service-to-service (S2S) communication, called “Actor tokens”, and a critical vulnerability in the (legacy) Azure AD Graph API that did not properly validate the originating tenant, allowing these tokens to be used for cross-tenant access.
September 17, 2025
security api azure entradirectory
Permalink: 2025/w38/one-token-to-rule-them-all-obtaining-global-admin-in-every-e

Related Links

  • VCF 9.0 Setting Custom Password Rotation Schedules via the API - VirtuallyWired api security
  • Bitwarden Integrates with OneCLI Agent Vault security api
  • OpenCVE - Vulnerability Intelligence Platform security api
  • NanoClaw Adopts OneCLI Agent Vault | NanoClaw Blog api security
  • GitHub - lance0/xfr: A modern iperf3 alternative with a live TUI, multi-client server, and QUIC support. Built in Rust. api security
← Back to Week 38

© 2026 Timo Sugliani · Weekly curated links, shared around the tech campfire