Security researcher Dirk-jan Mollema discovered two vulnerabilities in Microsoft’s Entra ID identity platform that could have granted attackers administrative access to virtually all Azure customer accounts worldwide. The flaws involved legacy authentication systems — Actor Tokens issued by Azure’s Access Control Service and a validation failure in the retiring Azure Active Directory Graph API.
Mollema reported the vulnerabilities to Microsoft on July 14. Microsoft released…








