Dirk-jan Mollema’s Post

View profile for Dirk-jan Mollema

Security researcher, hacker and founder at Outsider Security | Microsoft MVP and MVR

Almost 7 years ago I started my research into the Microsoft cloud. A few months ago I found the most critical vulnerability in Entra ID I could ever imagine: a token validation flaw allowing me to get Global Admin in every Entra ID tenant (yes, that includes your tenant). Read all the details in my latest blog: https://lnkd.in/eXgeHyJR

Danny Dreves

BeeHolder BV | Software Solutions

1w

Can you please delete my orphan B2C tenants with botched MFA on admin account ?

Rik van Duijn

Hacker & Co Founder at Attic Security

1w

Insane bug. Every tenant should have a (disabled) Dirk-Jan user to commemorate this.

Eito Tamura

OSCP | OSCE | OSWE | OSEP | BTL1 | BTL2 | Co-Founder & Principal Consultant at Tier Zero Security

1w

Awesome write-up, thanks for sharing! Have they extended it again?🤔 August 31, 2025: End of extended access to Azure AD Graph. Azure AD Graph will be fully retired.

Like
Reply

Nice catch 🥳 I really hope that you were first to discover this.

Like
Reply
Vaisha Bernard

Chief Hacker & Co-Owner at Eye Security | Microsoft MVR | BlackHat USA 2025 Speaker

1w

Awesome work and great writeup! What a finding 😅

Jos Lieben

Azure Cloud Architect at Natuurmonumenten

1w

Wauw, lekker bezig Dirk-jan! En how the fuck ga je (en wie dan ook) dit ooit nog toppen 😆

I think we have new nr 1 at Microsoft ;-) Really well done!! And as some already are saying: glad to have you on our side! #deeprespect!

Like
Reply
Maurice Hoeneveld

Portfolio Owner Sovereign Cloud Solutions. Senior Business & Management Consultant and team lead at Atos Cloud Advisory. Co-founder of 911Events motorsport events and support.

1w

Great find and amazing job. And it doesn’t only affect Azure cloud but since many organizations use Entra ID also for onsite authentication or their digital workplace the potential damage could be way larger.

Like
Reply
Florian Hansemann

@CyberWarship | KeyNoteSpeaker "Best Of The World In Security" | Top 21 Security Experts worldwide | #MCTTP

1w

The 1.000.000.000.000 Bounty 😅

See more comments

To view or add a comment, sign in

Explore content categories