> I SPy: Escalating to Entra ID's Global Admin with a first-party app
[DATE: 16/07/2025 00:00]
[LANGUAGE: EN]
Backdooring Microsoft's applications is far from over. Adding service principal credentials to these apps to escalate privileges and obfuscate activities has been seen in nation-state attacks, and led to the development of new security controls. Despite these efforts, we uncovered a vulnerable, built-in SP that could have allowed escalation from Application Administrator to any hybrid tenant user, including Global Admin.