TL;DR: Stryker’s outage shows how compromised administrative access in Microsoft 365, Entra ID, and Intune can turn legitimate device-management functions into destructive actions, according to Veza, after attackers allegedly wiped more than 200,000 devices across 79 countries and extracted 50 terabytes of data. The lesson is that privileged access paths, not just malware, can create enterprise-wide impact when wipe permissions are too broadly granted.
At a glance
What this is: This is an analysis of how attackers abused legitimate Microsoft 365, Entra ID, and Intune administrative access to trigger large-scale device wipes and disruption.
Why it matters: It matters because IAM, PAM, and lifecycle controls must account for built-in administrative functions that can become catastrophic when over-privileged or poorly monitored.
By the numbers:
- 79 countries.
- Attackers allegedly extracted 50 terabytes of sensitive information during the incident.
👉 Read Veza's analysis of the Stryker Intune wipe attack and identity controls
Context
This article is about privileged access abuse in device-management tooling, not a software exploit in the usual sense. When administrative permissions in Microsoft 365, Entra ID, and Intune are too broad, an attacker can use legitimate functions to trigger destructive actions at enterprise scale, which is exactly why identity governance must cover device-management pathways as well as sign-in controls.
For IAM and NHI programmes, the key issue is not whether the command is technically legitimate. The issue is whether the identity that can issue it is sufficiently constrained, reviewed, and monitored. In a mature programme, wipe capabilities, admin role scope, and conditional access policies should be treated as high-risk entitlements, not routine convenience settings.
Key questions
Q: What breaks when Intune wipe permissions are overexposed?
A: A compromised admin or delegated user can turn a normal management action into a destructive enterprise event. When wipe rights are broadly assigned, the attack does not need malware or exotic tooling, only access to the control plane. That is why destructive permissions must be governed as high-risk entitlements and reviewed with the same rigor as privileged identity paths.
Q: Why do broad admin roles increase the impact of identity compromise?
A: Broad roles collapse the boundary between authentication and action. Once an attacker enters with admin-level access, they can often reach device-management, mail, and directory functions without additional authorization checks. The practical risk is blast radius, because a single identity can affect many systems, many endpoints, and many users at once.
Q: How do security teams find hidden device-wipe paths?
A: They need to analyse the full entitlement graph, including direct permissions, inherited role grants, and delegated access in cloud identity systems. Role names alone are not enough, because destructive actions can be embedded in seemingly ordinary helpdesk or device-management assignments. Continuous access review should focus on actual actions, not just job titles.
Q: Who should approve privileged device-management actions?
A: Approval should sit with the smallest possible set of operational owners, and only for identities that truly need destructive authority. For high-risk actions, teams should require separate review, tight conditional access, and rapid revocation when the business need ends. The goal is to prevent standing access from becoming a standing outage risk.
Technical breakdown
How legitimate Intune permissions become a wipe mechanism
Intune is a built-in mobile device management platform, so actions such as wipe, retire, and remote configuration are expected administrative functions. If an attacker gains admin access in Entra ID or Microsoft 365, those same trusted control paths can be used to issue commands without malware or custom tooling. This is a classic example of living-off-the-land behaviour, where the platform’s own management features are repurposed as an attack mechanism. The security failure is not the existence of the function, but the fact that identity controls allowed a malicious operator to reach it.
Practical implication: treat device-management actions as privileged security events and monitor them with the same rigor as sensitive admin changes.
Why phishable MFA and broad admin roles increase blast radius
Administrative access becomes much more dangerous when it is paired with phishing-resistant gaps, such as SMS-based or phone-call MFA, and with roles that contain far more permissions than the user needs. In that combination, a single compromised identity can move from access to destructive action with very little friction. Conditional access policies are supposed to narrow that path, but if they are absent or weak, they do not materially limit the attacker’s options. The blast radius is created by the intersection of authentication weakness and entitlement overreach.
Practical implication: separate authentication strength from authorization scope and review both together during privileged access audits.
Why direct wipe actions need entitlement-level review
Some environments grant Intune permissions directly to users rather than only through tightly managed roles. That creates a second path to destructive action that can be missed if teams only review headline roles like Global Administrator. Direct action grants are especially risky because they often bypass the scrutiny applied to role-based access models. For identity teams, this is an access-path problem: the dangerous capability exists wherever entitlement graph complexity hides it, not just where the role name sounds privileged.
Practical implication: inventory direct device-wipe entitlements and remove any paths that are not explicitly justified by operational need.
Threat narrative
Attacker objective: The objective was to use trusted administrative access to destroy data, disable endpoints, and force operational shutdowns at scale.
- Entry occurred when attackers allegedly obtained administrative access in Microsoft 365, Entra ID, and Intune through compromised privileged identities.
- Escalation followed when those identities were able to use legitimate management capabilities, including remote wipe functions, without sufficient access constraints.
- Impact came from issuing wipe commands at scale, disabling devices and disrupting operations across a global enterprise footprint.
Breaches seen in the wild
- MITRE ATT&CK Enterprise Matrix — MITRE ATT&CK Enterprise — adversary tactics and techniques, threat detection, attack chain mapping, credential access, lateral movement, privilege escalation.
- Meta AI Instagram Account Takeover — 20,225 Instagram accounts hijacked via compromised Meta AI support chatbot with overprivileged access.
Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Device-wipe privilege is a destructive control plane, not a routine admin convenience. When Intune or similar MDM actions can disable endpoints at scale, the entitlement itself becomes a high-impact security control. That means identity governance has to classify wipe permissions alongside other privileged actions, with tighter review than ordinary operational access. Practitioners should treat destructive device actions as blast-radius controls, not helpdesk settings.
Phishable administrator access turns Microsoft 365 and Entra ID into an attack relay. The problem is not only that an admin was compromised, but that the authentication model allowed that compromise to travel into device-management authority. This is where MFA type, conditional access, and role scope intersect. If an attacker can reach admin functions with weak second factors, the enterprise has already accepted an avoidable escalation path. Practitioners should re-evaluate admin authentication as part of privileged action governance.
Identity visibility must extend from accounts to action graphs. Teams often know who has a role, but not which identity path leads to a wipe command, retire command, or equivalent destructive function. The article’s dashboard concept points to a broader governance gap: access reviews that stop at role labels miss direct entitlements and inherited permissions hidden in complex clouds. Practitioners should model the full permission graph, not just the named role.
Blast radius, not just breach entry, is the real unit of measurement here. A single compromised privileged identity should not be able to stop manufacturing, shipping, and end-user operations across dozens of countries. That means IAM and PAM teams need to ask whether any one administrator can trigger enterprise-wide disruption through native tooling. Practitioners should measure destructive-action reach, not only sign-in risk.
The NHI lesson is that operational tools are identities with consequences. Intune, Entra ID, and related cloud control planes are only as safe as the entitlements behind them. Once those entitlements can be abused, the control plane itself becomes a weapon. Practitioners should fold device-management permissions into NHI and privileged access governance, not leave them isolated in endpoint administration.
From our research:
- Lack of credential rotation is cited as the top cause of NHI-related attacks by 45% of organisations, followed by inadequate monitoring and logging (37%) and over-privileged accounts (37%), according to The State of Non-Human Identity Security.
- 85% of organisations lack full visibility into third-party vendors connected via OAuth apps, according to The State of Non-Human Identity Security.
- For a wider breach lens, the 52 NHI breaches Report helps teams trace how identity failures become operational incidents.
What this signals
Device-management permissions are now part of the identity attack surface. Organisations that still separate endpoint administration from IAM governance will miss the control path that matters most in incidents like this. The practical shift is toward entitlement graphs that include destructive actions, conditional access strength, and direct grants, not just directory roles.
Actionability depends on measuring destructive reach, not just access count. If a single account can issue wipe commands across thousands of endpoints, your governance model is already too coarse. Teams should prioritise reviews that answer which identities can affect the most devices with the fewest approvals, then reduce that number aggressively. For a broader context on entitlement sprawl, see Ultimate Guide to NHIs , Key Challenges and Risks.
Access review cadences must be paired with action-level telemetry. Role recertification alone will not catch an account that quietly retains destructive power in Intune or adjacent control planes. Pair reviews with logs that surface high-risk operations, and align them to NIST SP 800-53 Rev 5 Security and Privacy Controls where audit and access control expectations overlap.
For practitioners
- Audit destructive Intune permissions Map every role and direct entitlement that can issue wipe, retire, or equivalent device actions, then require explicit business justification for each one.
- Enforce phishing-resistant admin authentication Require hardware-backed or authenticator-based MFA for every administrative path that can reach Microsoft 365, Entra ID, or Intune control functions.
- Review access graphs, not just role names Trace inherited, delegated, and direct permissions across Entra ID and Intune so that hidden wipe paths are visible before they are abused.
- Constrain destructive commands with least privilege Separate day-to-day helpdesk access from high-risk device-management rights and remove standing permission wherever the function is not continuously required.
Key takeaways
- The Stryker incident shows that legitimate administrative tooling can become a destructive attack mechanism when identity governance is too permissive.
- The scale of the reported impact, including 200,000 devices and operations across 79 countries, shows why device-management rights belong in privileged access review.
- The control that matters most is not just MFA or role cleanup in isolation, but tighter governance of who can trigger destructive endpoint actions at all.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-03 | Over-privileged device-management access is the central issue in this incident. |
| NIST CSF 2.0 | PR.AC-4 | The attack exploited excessive access permissions and weak access governance. |
| NIST SP 800-53 Rev 5 | AC-6 | Least privilege directly applies to privileged device-management actions. |
| MITRE ATT&CK | TA0006 , Credential Access; TA0004 , Privilege Escalation; TA0040 , Impact | The incident followed credential compromise, privilege use, and destructive impact. |
| NIST Zero Trust (SP 800-207) | Zero Trust principles fit the need to continuously verify destructive admin actions. |
Use Zero Trust to continuously validate privileged access before destructive endpoint commands.
Key terms
- Destructive Device Management Action: A destructive device management action is an administrative command that can disable, wipe, or otherwise materially affect endpoints at scale. In identity governance terms, it is a privileged action, not a routine helpdesk task, because misuse can create immediate operational and security impact.
- Access Graph: An access graph is a relationship model that links identities, permissions, data objects, and system interactions. In NHI governance, it helps security teams see the full path from an agent or user to the action it can take, which is more useful than isolated account reviews.
- Living-off-the-Land: Living-off-the-land attacks use legitimate enterprise tools instead of custom malware. In identity environments, that means abusing approved administrative functions to perform disruptive actions while blending into normal operational traffic.
- Blast Radius: The potential scope of damage if a specific credential or identity is compromised. Identities with broad permissions have a larger blast radius and represent a higher priority for least-privilege enforcement and security controls.
What's in the full article
Veza's full analysis covers the operational detail this post intentionally leaves for the source:
- The dashboard queries that map Intune wipe permissions to specific Azure AD and Entra ID access paths.
- The permission combinations that expose remote wipe capability through direct grants and privileged roles.
- The remediation logic for tightening conditional access and reducing destructive action scope.
- The access-graph views used to identify accounts that can reach device-management controls without sufficient review.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an identity security programme, it is worth exploring.
Published by the NHIMG editorial team on August 25, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org