National Cyber Warfare Foundation (NCWF)

Beware the Hidden Risk in Your Entra Environment


0 user ratings
2025-06-25 11:05:59
milo
Privacy
If you invite guest users into your Entra ID tenant, you may be opening yourself up to a surprising risk. 
A gap in access control in Microsoft Entra’s subscription handling is allowing guest users to create and transfer subscriptions into the tenant they are invited into, while maintaining full ownership of them. 
All the guest user needs are the permissions to create subscriptions in



Source: TheHackerNews
Source Link: https://thehackernews.com/2025/06/beware-hidden-risk-in-your-entra.html


Comments
new comment
Nobody has commented yet. Will you be the first?
 
Forum
Privacy



Copyright 2012 through 2025 - National Cyber Warfare Foundation - All rights reserved worldwide.