As businesses around the world have shifted their digital infrastructure over the last decade from self-hosted servers to the cloud, they’ve benefitted from the standardized, built-in security features of major cloud providers like Microsoft. But with so much riding on these systems, there can be potentially disastrous consequences at a massive scale if something goes wrong. Case in point: Security researcher Dirk-jan Mollema recently stumbled upon a pair of vulnerabilities in Microsoft Azure’s identity and access management platform that could have been exploited for a potentially cataclysmic takeover of all Azure customer accounts. Known as Entra ID, the system stores each Azure cloud customer’s user identities, sign-in access controls, applications, and subscription management tools. Mollema has studied Entra ID security in depth and published multiple studies about weaknesses in the system, which was formerly known as Azure Active Directory. But while preparing to present at the Black Hat security conference in Las Vegas in July, Mollema discovered two vulnerabilities that he realized could be used to gain global administrator privileges—essentially god mode—and compromise every Entra ID directory, or what is known as a “tenant.” Mollema says that this would have exposed nearly every Entra ID tenant in the world other than, perhaps, government cloud infrastructure. “I was just staring at my screen. I was like, ‘No, this shouldn’t really happen,’” says Mollema, who runs the Dutch cybersecurity company Outsider Security and specializes in cloud security. “It was quite bad. As bad as it gets, I would say.”Read full article Comments
Microsoft’s Entra ID vulnerabilities could have been catastrophic

Advertisement
Related Articles
AI tools I wish existed
Article URL: https://sharif.io/28-ideas-2025 Comments URL: https://news.ycombinator.com/item?id=45421812 Points: 6 # Comments: 0
Notion Capital raises $130M growth fund to tackle …
The growth fund is nearly twice the size of its previous one.
Hiring only senior engineers is killing companies
Article URL: https://workweave.dev/blog/hiring-only-senior-engineers-is-killing-companies Comments URL: https://news.ycombinator.com/item?id=45421564 Points: 104 # Comments: 102
Show HN: Devbox – Containers for better dev …
I've been frustrated with dependency hell and clutter on my VPS from dev, so I …
Awakening Bell
Article URL: https://awakeningbell.org/ Comments URL: https://news.ycombinator.com/item?id=45421067 Points: 12 # Comments: 0
FAA decides it trusts Boeing enough to certify …
Article URL: https://www.theregister.com/2025/09/29/faa_decides_it_trusts_boeing/ Comments URL: https://news.ycombinator.com/item?id=45420327 Points: 113 # Comments: 54