Understanding the Major Entra ID Actor Tokens Vulnerability

Updated: Sep 18
In the world of cloud security, things move fast. Sometimes, cracks in big systems like Microsoft's Entra ID show up in ways that make you double-check your own setup. Security researcher Dirkjan van der Bijl recently revealed a vulnerability that allows attackers to snag Global Admin rights in nearly any Entra ID tenant. This issue is tied to undocumented "Actor tokens" and a sloppy validation problem in the old Azure AD Graph API. If you're a security pro working with Microsoft environments, this information is crucial. It’s not just about the technical details; it’s about shoring up your defenses before something similar happens again.
Breaking Down the Major Entra ID Actor Tokens Vulnerability
The Major Entra ID Actor Tokens Vulnerability involves behind-the-scenes tokens that Microsoft uses for service-to-service communications. For example, when Exchange needs to impersonate a user to interact with other parts of the system, it uses these tokens. They are JWTs that bypass many usual security checks, such as Conditional Access policies. While this is convenient for legitimate operations, it becomes a nightmare if exploited.
How the Attack Unfolded
Here’s how the attack played out, step by step:
An attacker obtains an Actor token from their own tenant. This is easy if they have a service principal set up.
They replace the tenant ID in the token to point to the victim's tenant. Finding the victim's ID is straightforward; it can be pulled from public domain lookups.
The key step involves obtaining a valid "netId" for a user in the target tenant. This is a unique user identifier, similar to a puid in tokens.
With that netId, they craft an impersonation token and hit the Azure AD Graph API. The API does not check if the token came from the correct tenant.
Next, they list all the Global Admins and their netIds.
Finally, they impersonate one of those admins to read or write anything. This includes creating new accounts, adding app credentials, or pulling sensitive data like BitLocker keys.
Finding those netIds was not complicated. Attackers could brute-force them since they are often sequential. They could also extract them from old leaked tokens or hop through B2B trusts by querying guest users' alternativeSecurityIds to reveal home tenant details.
The Fallout
The fallout from this vulnerability is significant. It allows for total tenant takeover with minimal trace for reads. The impact extends to M365 services like Exchange and SharePoint, and even Azure resources if the admin escalates privileges. Detection is challenging because the Graph API does not log activities like the newer Microsoft Graph does.
Microsoft acted quickly to patch this issue. They fixed the validation and restricted Actor token requests for the API to internal services only. They also issued CVE-2025-55241 for this vulnerability.
For those hunting remnants or similar anomalies, try this KQL query in Sentinel to spot suspicious audit logs:
```kql
// Example KQL query to find suspicious activity
```
This query flags changes that appear to originate from a Global Admin but actually come from service apps. This is a red flag for potential token misuse.
What This Means for Your Team
Incidents like this remind us why we cannot simply set and forget our cloud security. Unmonitored APIs and loose trusts create a recipe for quiet compromises that can lead to significant problems, such as data leaks or ransomware attacks. Even with the fix in place, variants may still emerge. Therefore, staying vigilant with monitoring and responding quickly is essential.
Strengthening Your Defenses with Inception Protection
At Inception Security, our Inception Protection MDR service is designed specifically for these types of threats in Microsoft environments. We leverage your existing licenses for Defender for Endpoint, Sentinel, Conditional Access, and Azure tools to create a robust security layer without unnecessary bloat.
Our team monitors for unusual API activity, token manipulations, and subtle log patterns that indicate trouble. We handle threat hunting and incident response, ensuring you get back on track swiftly.
Assessing Your Security Posture
Want to see where your environment stands? Grab our free Inception Foresight M365 Assessment. This straightforward scan identifies vulnerabilities, configuration slips, and risks like those associated with the Actor token vulnerability. No strings attached—just real insights to help tighten your security.
Sign up for your free assessment and let’s discuss how we can assist you.
For more information on threats like this, follow us on LinkedIn at Inception Security and on X @inceptionsec. If this resonates with you, share it—let's keep our community informed and secure.



