By NHI Mgmt Group Editorial TeamBased on SlashID: “Ready to start a top-tier security upgrade?” (March 11, 2026)

TL;DR: Stryker’s March 2026 attack showed how valid Microsoft identity access can be turned into a non-encrypting wiper, with public reporting citing nearly 80,000 devices wiped through Intune and at least 50 terabytes of corporate data deleted. The incident demonstrates that perimeter controls and MFA alone do not stop privileged cloud administration abuse, according to SlashID.


At a glance

What this is: This is an analysis of how Stryker’s Intune environment was abused as a living-off-the-land wiper, with the key finding that legitimate Microsoft administration paths were turned into destructive action at enterprise scale.

Why it matters: It matters because IAM and PAM teams have to treat cloud management planes as high-impact identity surfaces, where valid access can create the same blast radius as malware if privilege, session trust, and admin approvals are weak.

By the numbers:

  • At least 50 terabytes of corporate data were deleted from internal storage.

Context

Stryker’s attack is a cloud identity control-plane problem, not a traditional malware problem. The destructive step was executed through Microsoft-managed administration functions, which means the real failure was in how privileged access to the management plane was governed, trusted, and monitored.

For IAM, PAM, and NHI teams, the important question is not whether authentication succeeded. It is whether a valid identity should have been able to issue a mass wipe, whether that access was standing or over-privileged, and whether the environment could distinguish normal administration from destructive abuse.


Key questions

Q: What breaks when Intune wipe permissions are overexposed?

A: A compromised admin or delegated user can turn a normal management action into a destructive enterprise event. When wipe rights are broadly assigned, the attack does not need malware or exotic tooling, only access to the control plane. That is why destructive permissions must be governed as high-risk entitlements and reviewed with the same rigor as privileged identity paths.

Q: Why can MFA fail to stop a cloud admin takeover?

A: Because the attacker may reuse a valid post-authentication session rather than replaying the password or challenge. If the session token is already trusted, MFA has effectively been completed, and the real risk shifts to privileged action control, session revocation, and admin behaviour monitoring.

Q: What are the signs that Microsoft admin access is being abused?

A: Look for first-time access to Intune, Graph, or Entra admin paths, abnormal admin volumes, unusual user agents, risky geolocation, impossible travel, and destructive actions such as bulk wipe or factory reset outside the normal change pattern. Those signals usually matter more than whether the login itself succeeded.

Q: How should teams respond to a compromised Intune administrator account?

A: Treat it as a control-plane incident, not just an endpoint event. Revoke sessions, disable or reset the affected identity, remove risky role assignments, review recent Intune and Graph actions, and verify whether any bulk device commands or permission grants were issued before containment completed.


Technical breakdown

How Intune becomes a wiper channel

Microsoft Intune is a device-management plane, so remote wipe and factory reset are ordinary administrative actions when issued by an authorised identity. In this attack pattern, the threat actor does not need custom malware on the endpoint. They only need access to the management console or Microsoft Graph path that can invoke device actions such as wipe, retire, or reset. Because the commands are native, endpoint tools can read them as legitimate administration unless identity context is added to detection.

Practical implication: Treat device-management APIs and admin portals as destructive-control surfaces, not routine SaaS endpoints.

Why valid Microsoft identity access bypassed perimeter controls

The article describes initial access hypotheses that include adversary-in-the-middle phishing and VPN compromise, both of which can deliver valid Microsoft identity material rather than obvious malware. Once a session token or privileged credential is replayed, MFA may already have been satisfied, and perimeter controls have little visibility into whether the resulting admin action is normal. That is the core weakness of cloud control-plane abuse: the attack is authenticated, authorised, and operationally quiet until the destructive command lands.

Practical implication: Focus detection on abnormal privileged sign-in and admin behaviour, not just failed logins or blocked malware.

Privilege on the management plane is the real blast-radius multiplier

The article makes clear that a normal user account could not have triggered the wipe at scale. The attacker needed either an already privileged account or a path to over-privileged Microsoft Graph, Entra, or Intune permissions. Once that access exists, a single identity can move from administrative visibility to enterprise-wide destruction in one session. That is why standing privilege in cloud admin roles is so dangerous: the control plane itself becomes the impact surface.

Practical implication: Review who can issue bulk device actions, assign roles, and grant Graph permissions before the next compromise path reaches them.


Threat narrative

Attacker objective: The objective was systemic disruption through trusted cloud administration, not financial extortion or stealthy theft.

  1. Entry likely began with stolen Microsoft identity material, either through adversary-in-the-middle phishing or compromised VPN access that yielded a valid session or account.
  2. Credential abuse then allowed the actor to authenticate into Microsoft 365, Entra ID, or related admin surfaces as a legitimate user rather than a noisy intruder.
  3. Escalation depended on privileged account access or over-privileged Graph and Intune permissions that could issue destructive device-management commands.
  4. Impact came when Intune’s native wipe and factory reset functions were used to reset endpoints and delete data at enterprise scale.

Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Identity control-plane abuse is now a destructive attack class, not a management anomaly. The Stryker incident shows that a cloud device-management plane can be weaponised when a valid identity reaches native wipe and reset functions. This is not about malware delivery failure; it is about destructive authority being concentrated in the same identity layer used for routine administration. Practitioners should stop treating management-plane access as low-risk SaaS use and start treating it as a high-consequence control surface.

Standing privilege, not authentication failure, is the assumption that collapsed. The model that access review can safely police cloud admin access assumes the privilege remains stable, observable, and reversible before abuse. In this attack, the destructive command path suggests that an identity with sufficient privilege already existed or was readily reachable, and that assumption failed because the control plane accepted ordinary-looking administrative action as legitimate. The implication is that privilege must be constrained before it reaches bulk device actions.

Remote wipe becomes a governance failure when one identity can exercise enterprise-wide destructive authority. The article’s central failure mode is not simply that a wipe command exists, but that one compromised or over-privileged identity could execute it at scale. That exposes a governance gap in how Intune, Entra ID, and Graph permissions are segmented, reviewed, and approval-gated. Practitioners should interpret this as a blast-radius problem in cloud administration, not a device-security issue.

Phishing-resistant authentication is necessary but not sufficient when the post-authentication session is the real asset. The article’s initial-access discussion makes clear why MFA can be bypassed in practice through token or session theft, especially when the attacker’s goal is privileged administration rather than endpoint malware. The stronger lesson is that session trust and admin authorisation must be evaluated together. IAM teams should treat authenticated Microsoft sessions as security objects with their own lifecycle and risk.

Control-plane visibility has to be identity-aware, because native API actions will otherwise look benign. Intune wipe commands, Graph calls, and Entra administration can all appear as valid cloud operations unless the programme understands what identity, role, device state, and change window should be allowed. The named concept here is identity blast radius: the amount of destruction a single identity can trigger if cloud admin controls are not segmented. Practitioners should narrow that radius before another valid account reaches the same function.

What this signals

Identity blast radius is the right lens for cloud device management. When one account can wipe thousands of endpoints, the issue is not merely privileged access but the size of the damage envelope tied to that identity. Programmes need to map which roles can issue destructive actions and separate them from everyday administration before a compromised session reaches them.

Microsoft Intune, Entra ID, and Graph should be treated as one governance surface rather than three disconnected tools. That means change control, approval design, and privileged access review have to span the full control plane, because a valid administrative action in one layer can become an irreversible event in another.

Access reviews alone are too slow if a session can be replayed, abused, and completed before the next certification cycle. The practical shift is toward issuance-time controls, tighter admin scoping, and rapid session revocation when privileged behaviour deviates from the normal pattern.


For practitioners

  • Restrict mass device actions Separate routine endpoint administration from destructive functions such as wipe, factory reset, and bulk retire. Require additional approval or tightly scoped roles before any identity can invoke enterprise-scale device actions in Intune or Graph.
  • Review privileged Microsoft roles Inventory which accounts can assign roles, grant Graph permissions, or operate Intune at scale. Remove standing access from admin roles that do not need continuous control-plane authority.
  • Detect session-based admin abuse Alert on first-time use of Intune, Graph, or Entra admin paths, unusual user agents, risky geolocations, impossible travel, and bulk device operations from a previously quiet account.
  • Harden the post-authentication session Assume MFA may already have been satisfied and design for token theft, not just password theft. Add controls that revoke suspicious sessions quickly and challenge privileged actions even after login succeeds.
  • Limit Graph permission sprawl Audit high-risk Microsoft Graph scopes such as DeviceManagementManagedDevices.ReadWrite.All, Directory.ReadWrite.All, and RoleManagement.ReadWrite.Directory, then narrow them to the minimum required administrative use cases.

Key takeaways

  • The Stryker incident shows how a valid Microsoft admin path can become a destructive wiper channel when the control plane is over-trusted.
  • Public reporting cited nearly 80,000 devices wiped and at least 50 terabytes of corporate data deleted, showing the scale a single compromised management plane can reach.
  • The limiting control is not endpoint detection alone but tight governance over who can issue destructive cloud administration commands and when.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0 sets the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-05 — Overprivileged NHIThe attack depended on excessive Microsoft admin authority able to trigger mass device actions.
NHI-04 — Insecure AuthenticationThe article centers on stolen or replayed Microsoft identity material reaching the control plane.
NHI-01 — Improper OffboardingThe destructive path highlights the risk of identities retaining access beyond their needed use window.
Recommendation — Reduce standing admin scope and separate destructive Intune actions from routine device management. Harden authentication against session theft and require stronger proof before privileged admin actions. Revoke dormant or unnecessary privileged identities before they can be reused in the management plane.
MITRE ATT&CKTA0006;TA0008;TA0040 — Credential Access; Lateral Movement; ImpactThe attack chain moved from credential abuse into cloud-admin execution and destructive impact.
Recommendation — Map privileged cloud-control abuse to credential access, lateral movement, and impact techniques.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe incident shows the consequence of poorly bounded entitlements on cloud administration surfaces.
Recommendation — Tighten entitlements for Intune and Graph so destructive actions require explicit, least-privilege authorisation.

Key terms

  • Control Plane Abuse: Control plane abuse occurs when an attacker uses legitimate administrative interfaces to perform destructive or high-impact actions. In NHI terms, the problem is not malware execution but trusted authority that can scale changes across many systems at once.
  • Living-off-the-Land Wiper: A destructive attack that uses native administration tools instead of custom malware to erase devices or data. The method reduces obvious malware signals and shifts detection pressure onto identity, command, and change-pattern monitoring.
  • Identity Blast Radius: The amount of damage a compromised identity can cause across systems, data, and infrastructure. In NHI environments, it is shaped by permissions, network reach, and administrative capability rather than by the credential alone. Reducing blast radius is a containment strategy that limits lateral movement and data exposure.
  • Post-Authentication Session: The authenticated state created after a user completes login and MFA. When that session is stolen or replayed, the attacker may bypass the original login challenge and act as the user until the session is revoked or expires.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 6, 2026.
Updated on October 6, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org