
Critical Microsoft Entra ID Flaws Prompt Rapid Global Patch
Security researcher Dirk-jan Mollema uncovered two serious flaws in Microsoft’s Entra ID identity platform that could have allowed attackers to obtain global administrator rights across cloud tenants. The vulnerabilities involved misuse of Actor Tokens and a validation error in the legacy Azure AD Graph API. Microsoft’s Security Response Center quickly investigated, confirmed no evidence of abuse, and deployed a fix across its cloud ecosystem. The incident highlights risks tied to legacy authentication mechanisms and underscores Microsoft’s push to retire outdated protocols under its Secure Future Initiative.







