None
EN
Entra ID Bug Could Have Exposed Every Microsoft Tenant
['Ken Underhill']
eSecurity Planet
Azure AD Graph API Validation Gap: The legacy Azure AD Graph API contained a flaw in its validation of Actor tokens.
This combination of unrestricted privilege and stealth makes CVE-2025-55241 risky, giving an adversary the potential to silently compromise an organization’s entire Microsoft cloud footprint.
In addition to applying the patch, security teams should:Audit Legacy Apps : Verify no applications still depend on the deprecated Azure AD Graph API.
: Verify no applications still depend on the deprecated Azure AD Graph API.
Migrate to Microsoft Graph: Shift from the Azure AD Graph API to Microsoft Graph for stronger logging and auditing.
['tokens'
'id'
'microsoft'
'azure'
'ad'
'actor'
'takeover'
'entra'
'cloud'
'graph'
'api'
'patches'
'severe'
'bug'
'tenant']