Microsoft’s Entra ID vulnerabilities could have been catastrophic

Microsoft’s Entra ID vulnerabilities could have been catastrophic

As organizations globally transition from traditional self-hosted servers to cloud-based infrastructures, they often rely on the robust security features provided by leading cloud service providers like Microsoft. However, the reliance on these systems brings significant risks; a single vulnerability could lead to widespread chaos. Recently, security researcher Dirk-jan Mollema uncovered alarming vulnerabilities within Microsoft's Azure identity and access management platform, known as Entra ID. These weaknesses could have allowed malicious actors to gain unauthorized global administrator privileges, threatening the integrity of all Azure customer accounts. Entra ID is responsible for managing user identities, access controls, applications, and subscription management for Azure cloud users. Mollema, who has extensively researched Entra ID's security, was preparing for a presentation at the Black Hat security conference in Las Vegas when he stumbled upon these critical flaws. He realized that with these vulnerabilities, it was possible to compromise any Entra ID directory, referred to as a 'tenant.' Mollema expressed his shock upon discovering the extent of the vulnerabilities, stating, "I was just staring at my screen. I was like, ‘No, this shouldn’t really happen.’ It was quite bad. As bad as it gets, I would say." He elaborated on the potential impacts, explaining that anyone could use these vulnerabilities to impersonate users within other tenants, modify configurations, and create new administrative accounts at will. This incident highlights the ongoing challenges in cloud security and underscores the necessity for vigilance in the safeguarding of digital infrastructures. Thankfully, the discovery of these vulnerabilities has led to urgent discussions about strengthening security measures to prevent potential exploitation.

Sources : Ars Technica

Published On : Sep 20, 2025, 11:20

Mobile
Google Maps Unveils Major Navigation Overhaul with AI-Powered Features

In a significant update, Google Maps has introduced a comprehensive redesign aimed at enhancing user navigation and inte...

Ars Technica | Mar 12, 2026, 12:40
Google Maps Unveils Major Navigation Overhaul with AI-Powered Features
Cybersecurity
Israeli Cybersecurity Firm Bold Secures $40 Million Amid Ongoing Conflict

Bold, an emerging cybersecurity startup from Israel, has successfully raised $40 million in funding, marking its debut d...

Business Insider | Mar 12, 2026, 12:15
Israeli Cybersecurity Firm Bold Secures $40 Million Amid Ongoing Conflict
Gaming
Nintendo Stock Soars 18% Amidst Surprising Success of New Pokémon Game

Nintendo's shares have surged by 18% this week, driven by the unexpected success of a new Pokémon game that has sparked ...

CNBC | Mar 12, 2026, 12:05
Nintendo Stock Soars 18% Amidst Surprising Success of New Pokémon Game
Computing
Market Insights: Oil Prices Surge Amid Economic Shifts and Tech Investments

In a significant update for investors, Atlassian has announced a 10% reduction in its workforce, citing the need to self...

CNBC | Mar 12, 2026, 12:25
Market Insights: Oil Prices Surge Amid Economic Shifts and Tech Investments
AI
Sam Altman Highlights Challenges Facing AI Acceptance in the U.S.

The landscape of artificial intelligence in the United States is currently marked by skepticism, according to OpenAI CEO...

Business Insider | Mar 12, 2026, 09:20
Sam Altman Highlights Challenges Facing AI Acceptance in the U.S.
View All News