Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
identity-authentication-vulnerabilityprivilege-escalation-methodcloud-service-vulnerabilityinitial-access-method

Microsoft Entra Agent ID Blueprint Model Expands Cross-Tenant Compromise Risk

Updated 7d agoFirst seen Jun 9, 20264 sources

New research warns that Microsoft Entra Agent ID can significantly widen the impact of a single credential compromise because authentication is anchored to an agent blueprint while privileges can be distributed across many child agent identities. Security researchers found that one blueprint principal can authenticate up to 250 agent identities per tenant, optionally span multiple tenants, and inherit a mix of service principal permissions, user-like capabilities, Entra role assignments, and delegated permissions. Datadog and Compass Security both reported that this design creates a larger blast radius than traditional Entra applications, especially when third-party or multitenant blueprints are used, because the publishing tenant controls the credential material trusted by consuming tenants.

Researchers also demonstrated practical abuse paths. Compass Security showed that attackers who gain blueprint ownership or credential-management access could add credentials, create child agent identities through the AgentIdentity.CreateAsManager role claim, and potentially escalate privileges up to Global Administrator; it also described consent-phishing with a foreign multitenant blueprint to inherit permissions such as Application.ReadUpdate.All. Separately, Red Canary documented a suspicious non-interactive Microsoft Graph sign-in tied to an assistive agent, where the application Agent001 authenticated with a federated identity credential, satisfied MFA via token claims rather than user interaction, and requested broad scopes including Group.Read.All, Mail.ReadWrite, Mail.Send, MailboxSettings.ReadWrite, and User.Read, underscoring how Agent ID workflows can blur the line between application and user access.

Share:
Microsoft Entra Agent ID Blueprint Model Expands Cross-Tenant Compromise Risk
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

3 events from the most recent confirmed update back to the earliest known activity.

3 EVENTS
Jun 11, 202614d ago

Datadog details Entra Agent ID blueprint blast radius risks

Datadog Security Labs published an analysis warning that Entra Agent ID's blueprint-based identity model can create a larger compromise blast radius than the traditional Entra application model. The post highlighted that a single compromised blueprint credential could expose up to 250 agent identities per tenant, optional agent users, and cross-tenant identities with accumulated privileges.

Entra Agent ID: The blueprint blast radius | Datadog Security Labs
May 8, 20262mo ago

Suspicious Entra Agent ID sign-in to Microsoft Graph observed

On 2026-05-08, an Azure AD non-interactive sign-in recorded successful authentication for user Matt Graeber to Microsoft Graph via the application Agent001 using a federated identity credential. The event originated from IP 51.3.97.221, used a PowerShell/7.6.1 user agent on macOS, and requested broad Microsoft Graph scopes including Group.Read.All, Mail.ReadWrite, Mail.Send, MailboxSettings.ReadWrite, and User.Read.

Investigating suspicious AI workflows in Microsoft Entra Agent ID: Assistive agents | Red Canary
Apr 10, 20224y ago

Compass Security publishes Agent ID security analysis

Compass Security published research describing Microsoft Entra Agent ID's security model and attack paths, including blueprint credential compromise, blueprint ownership abuse, and consent phishing with foreign multitenant blueprints. The analysis also reported that dangerous Graph permissions and Azure RBAC role assignments remained assignable in testing despite some Microsoft restrictions.

Entra Agent ID from a Security Perspective - Compass Security Blog
LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

11 LINKEDOpen in app
Threat actors
2 linked
Affected products
5 linked
Microsoft-GraphMicrosoft Entra IdAzure DevopsPowershellMacos
Organizations
4 linked
Microsoft CorporationDatadogCompass SecurityContosoCorp
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.