Entra ID & IdentityHow-To & HardeningNews

How to Review Entra Provisioning Service Permissions After August 2026 Patch Tuesday

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

August 2026's Entra ID fixes included a critical elevation-of-privilege flaw in the Entra Provisioning Service. Even though Microsoft fixed it server-side, it's a good moment to review provisioning permissions in your tenant.

What the provisioning service does

Entra provisioning creates, updates and removes accounts automatically:

  • HR-driven inbound provisioning (Workday, SuccessFactors, API-driven) into Entra ID or Active Directory.
  • Outbound app provisioning (SCIM) to SaaS applications.
  • Cross-tenant synchronization between your tenants.
  • Entra Connect / cloud sync between Active Directory and Entra ID.

Each can create users, change attributes and modify group memberships — powerful capabilities.

Step 1: Inventory provisioning jobs

In the Entra admin center, review Enterprise applications with provisioning configured, cross-tenant synchronization configurations, and Entra Connect / cloud sync settings.

Step 2: Review scope

For each job:

  • Which users and groups are in scope?
  • Which attributes are written, and could any affect access (for example, group memberships, manager, department used in dynamic groups or Conditional Access)?
  • Can it create privileged users or add users to privileged groups?

Step 3: Review credentials

  • SCIM tokens and secrets: who has them, where are they stored, when do they expire?
  • API-driven provisioning apps: which permissions (for example, SynchronizationData-User.Upload)?

Step 4: Restrict administration

Limit who can configure provisioning (Application Administrator, Hybrid Identity Administrator) and manage those roles with PIM.

Step 5: Monitor

  • Provisioning logs for unexpected creates and updates.
  • Audit logs for provisioning configuration changes.
  • Alerts when provisioning adds users to privileged groups.

Step 6: Protect privileged groups

Use role-assignable groups (which only privileged roles can manage) for groups that grant admin access, and exclude them from provisioning scope.

Sources

  1. Source
entra provisioning securityEntra ID CVSS 10 flaw2026

More on this story