Entra ID & IdentityCIO BriefingsRetrospectives

CIO Brief: Even Identity Platforms Have Catastrophic Bugs

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from September 2025, written in 2026 with the benefit of hindsight.

The short version: In 2025, a researcher found a flaw in Microsoft Entra ID — the system that controls sign-in for Microsoft 365 and Azure — that could have let an attacker become an administrator in any company's tenant, with little trace in the logs. Microsoft fixed it before any known misuse.

Why this matters

Even the most widely used identity platforms can contain catastrophic bugs, often in older components. Customers can't prevent them, and some leave little evidence. What you can control is how quickly you'd notice the consequences.

The business impact

  • Potential total compromise of your cloud environment.
  • Limited visibility into provider-side flaws.
  • Dependence on provider security and researcher disclosures.

Questions to ask your team

  • Would we be alerted immediately if a new administrator appeared in our tenant?
  • Do we monitor changes to sign-in policies, applications and federation settings?
  • Do we still use older Microsoft identity technologies that Microsoft is retiring?
  • How do we track Microsoft's security advisories?

What good looks like

Alerts on every privileged change in your identity system, retirement of legacy identity components, monitoring of advisories and a plan for responding to provider-level incidents.

The decision

Ask your team to demonstrate the alert that fires when someone becomes a Global Administrator. If there isn't one, create it this week.

entra id actor token vulnerability impactEntra actor token flaw2025

More on this story