Security experts have recently identified significant flaws in Microsoft’s Entra ID (previously known as Azure Active Directory) under the designation “UnOAuthorized.” These vulnerabilities could permit unauthorized actions that surpass the intended security measures.
The core issue, related to OAuth 2.0 scope permissions, could have empowered attackers to escalate their privileges and maintain a foothold within Microsoft’s ecosystem. The most concerning aspect of this flaw was the potential to manipulate user roles, including adding or removing individuals from the Global Administrator position—Entra ID’s top-level access role.
Exploitation of this vulnerability could have facilitated unauthorized privilege escalation and lateral movement within Microsoft 365, Azure, and associated SaaS applications.
To exploit this flaw, attackers needed to hold either the Application Administrator or Cloud Application Administrator roles within Entra ID. These roles, despite their high level of access, often lack stringent security measures, making them prime targets for exploitation.
Microsoft Entra ID Security Flaw: UnOAuthorized
The vulnerability, uncovered by Semperis, was found in the OAuth 2.0 scope permissions of Entra ID. This flaw allowed attackers to perform actions beyond the authorized controls, including the capability to alter privileged roles such as the Global Administrator.
The research revealed that certain Microsoft application service principals had permissions that were not clearly defined, allowing unauthorized actions such as adding users to the Global Administrator role.
This vulnerability affected several Microsoft services, including Viva Engage (formerly Yammer), Microsoft Rights Management Service, and Device Registration Service. The Device Registration Service issue was classified as a critical vulnerability due to its potential to modify privileged role memberships.
“By assigning credentials to Microsoft’s Device Registration Service, we could access Microsoft Graph as that service,” noted Semperis researchers.
Privilege Escalation via Microsoft Applications
The investigation showed that specific Microsoft application service principals could perform privileged actions, including adding users to the Global Administrator role, without explicit authorization.
While there is no evidence of actual breaches resulting from these vulnerabilities, the potential for impact was substantial. Attackers could have used these access points to install persistent threats or manipulate roles undetected.
Organizations are advised to carefully review their Entra ID audit logs and monitor for any suspicious activity related to service principal credentials, especially those linked to the Device Registration Service.
Following the discovery, Semperis alerted the Microsoft Security Response Center (MSRC), which has since implemented enhanced controls to limit credential usage on service principals, thereby reducing the risk of unauthorized access.
To further mitigate risks, organizations should apply the same level of security to Application Administrators and Cloud Application Administrators as they do to Global Administrators. Employing best practices, such as privilege separation, using secure workstations for privileged access, and ensuring robust, phishing-resistant authentication, is essential.
These findings highlight the need for continuous vigilance and robust security practices to protect digital infrastructures. Semperis and Microsoft are committed to strengthening security measures to safeguard users against emerging threats.



