CIO Brief: Even Identity Platforms Have Catastrophic Bugs
Retrospective: this article looks back at events from September 2025, written in 2026 with the benefit of hindsight.
The short version: In 2025, a researcher found a flaw in Microsoft Entra ID — the system that controls sign-in for Microsoft 365 and Azure — that could have let an attacker become an administrator in any company's tenant, with little trace in the logs. Microsoft fixed it before any known misuse.
Why this matters
Even the most widely used identity platforms can contain catastrophic bugs, often in older components. Customers can't prevent them, and some leave little evidence. What you can control is how quickly you'd notice the consequences.
The business impact
- Potential total compromise of your cloud environment.
- Limited visibility into provider-side flaws.
- Dependence on provider security and researcher disclosures.
Questions to ask your team
- Would we be alerted immediately if a new administrator appeared in our tenant?
- Do we monitor changes to sign-in policies, applications and federation settings?
- Do we still use older Microsoft identity technologies that Microsoft is retiring?
- How do we track Microsoft's security advisories?
What good looks like
Alerts on every privileged change in your identity system, retirement of legacy identity components, monitoring of advisories and a plan for responding to provider-level incidents.
The decision
Ask your team to demonstrate the alert that fires when someone becomes a Global Administrator. If there isn't one, create it this week.
- Entra ID Actor Token Flaw (Sept 2025): A Cross-Tenant Global Admin Bug Incident Teardowns
- How to Monitor Entra ID for Cross-Tenant and Undocumented Token Abuse How-To & Hardening
- Detecting Cross-Tenant Token Abuse: Entra Sign-In Logs and Sentinel KQL Detection & Response