CVE-2025-55241: Privilege Escalation in Microsoft Entra ID

ISGroup Cybersecurity

Discovered by security researcher Dirk-Jan Mollema, this critical vulnerability in Microsoft Entra ID (formerly Azure Active Directory) allowed attackers to impersonate any user, including global administrators, across different tenants. The flaw stemmed from two interacting issues:

  1. Actor Tokens: Undocumented tokens used by internal Microsoft services.
  2. Azure AD Graph API Error: The legacy Azure AD Graph API did not validate the source tenant of requests, allowing Actor Tokens from one tenant to be accepted by another.

This combination allowed attackers to authenticate as arbitrary users in target tenants.

ProductMicrosoft Entra ID
Date2025-09-22 10:22:30
Information
  • Fix available

Technical Summary

The vulnerability allowed attackers to:

  • Impersonate any user: Including global administrators, in any Entra ID tenant.
  • Bypass security controls: Such as conditional access policies and multi-factor authentication (MFA).
  • Access sensitive data: Including user data, group and role details, tenant settings, application permissions, and device information.
  • Modify tenant configurations: Create new accounts, grant additional permissions, or exfiltrate sensitive data.

This flaw could have led to the complete compromise of the tenant, with repercussions for services such as Microsoft 365 and Azure.

Recommendations

  • In the long term, the incident reinforces two operational lessons for cloud identity: reduce the attack surface by retiring legacy APIs and demand robust, tenant-aware token validation from identity providers, accompanied by telemetry.
  • For defenders, the immediate actions are simple: verify the status of Microsoft’s patch in your tenant, inventory and migrate away from the Azure AD Graph API, and review privileged roles and service principals to detect unexpected changes.

Protect your organisation with Threat Intelligence and Digital Risk Protection.

Choose ISGroup for a practical, tailored engagement:

  • A focused assessment of your environment and requirements
  • Clear findings with a prioritised, actionable roadmap
  • Direct support from experienced specialists through remediation and implementation
Talk to an expert