Entra ID & IdentityIncident TeardownsRetrospectives

Entra ID Actor Token Flaw (Sept 2025): A Cross-Tenant Global Admin Bug

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from September 2025, written in 2026 with the benefit of hindsight.

In September 2025, security researcher Dirk-jan Mollema published details of a critical flaw in Microsoft Entra ID that could have allowed an attacker to impersonate any user — including Global Administrators — in any Entra ID tenant. Microsoft had fixed it in July 2025 after his report and assigned CVE-2025-55241.

How it worked (at a high level)

The issue combined two elements:

  • Actor tokens: undocumented tokens issued by a legacy Microsoft service (Access Control Service) for service-to-service communication. They could be used to impersonate users in other tenants under certain conditions, and weren't subject to normal Conditional Access policies.
  • A validation flaw in the legacy Azure AD Graph API, which didn't properly check that the token's tenant matched the target tenant.

Together, an attacker who obtained an actor token from their own tenant could use it to act as users in another tenant via Azure AD Graph. Critically, requests made this way generated little or no logging in the victim tenant.

Microsoft's response

Microsoft fixed the validation flaw, said it found no evidence of exploitation, and accelerated retirement of the legacy Azure AD Graph API.

Why it mattered

  • Cross-tenant impact: the flaw affected essentially every Entra ID tenant.
  • Legacy components — Azure AD Graph and Access Control Service — created the risk.
  • Lack of logging meant customers couldn't have detected exploitation themselves.

Lessons in hindsight

  • Legacy APIs carry hidden risk; migrate applications off Azure AD Graph to Microsoft Graph.
  • Identity platforms can have catastrophic bugs — defense in depth (monitoring downstream services, least privilege) still matters.
  • Researchers and responsible disclosure remain essential.
entra id actor token vulnerabilityEntra actor token flaw2025

More on this story