In July 2025, security researcher Dirk-jan Mollema found what he called "the most impactful Entra ID vulnerability that I will probably ever find." It combined two things. First, undocumented "Actor tokens," issued by a legacy Microsoft service for service-to-service communication, which let a Microsoft service impersonate any user for 24 hours, without logs when issued, without Conditional Access and without the ability to revoke them. Second, a validation failure in the legacy Azure AD Graph API, which accepted an impersonation token built on an Actor token from one tenant as valid in any other tenant. Together, "with a token I requested in my lab tenant I could authenticate as any user, including Global Admins, in any other tenant," he wrote. Mollema reported it on 14 July; Microsoft deployed a fix globally on 17 July and issued CVE-2025-55241 on 4 September. Microsoft's telemetry did not detect any abuse.
Key takeaways
- Actor tokens, a legacy Microsoft service-to-service mechanism, allowed impersonation of any user for 24 hours without logging or Conditional Access.
- The Azure AD Graph API failed to check which tenant an Actor token came from, so a token from an attacker's own tenant worked everywhere.
- With a user's tenant ID and netId, an attacker could impersonate Global Admins and take over a tenant, leaving little or no trace until changes were made.
- Microsoft fixed the flaw within days of the 14 July 2025 report and issued CVE-2025-55241; it saw no evidence of abuse.
- The identity lesson: hidden service-to-service tokens are non-human identities too, and ones that cannot be logged, restricted or revoked are a single point of failure.
At a glance
| Organisations | Microsoft (Entra ID, Azure AD Graph API); every Entra ID tenant, except probably national cloud deployments, according to the researcher |
|---|---|
| When | Reported 14 July 2025; fixed 17 July 2025; CVE issued 4 September 2025; details published 17 September 2025 |
| Attacker | None known. Found by researcher Dirk-jan Mollema |
| Entry point | Actor tokens requested in an attacker-controlled tenant, accepted cross-tenant by the Azure AD Graph API |
| Identities abused | Microsoft service-to-service Actor tokens; impersonation of any user, including Global Admins |
| Impact | Potential full takeover of any Entra ID tenant with minimal logging; Microsoft detected no abuse |
| Category | NHI. Incident class: vulnerability found by researchers (vulnerability, no confirmed breach) |
What happened
Mollema came across Actor tokens while researching hybrid Exchange setups. Exchange requests them when it needs to act as a user towards other services, and embeds them in unsigned impersonation tokens. He listed the problems with the design: "There are no logs when Actor tokens are issued," the impersonation tokens can be created without contacting Entra ID, "They cannot be revoked within their 24 hours validity," and "They completely bypass any restrictions configured in Conditional Access."
While testing, he changed the tenant ID in an impersonation token to a tenant where none of his accounts existed, and the Azure AD Graph API accepted it. All an attacker needed was the target's tenant ID, which is public, and the netId of one user. NetIds are incremental and could be brute-forced, Mollema wrote, and guest accounts store the netId of their home account, so one compromised tenant revealed the identifiers for many others. With a Global Admin's netId, an attacker could perform any read or write action over the Azure AD Graph. "None of these actions would generate any logs in the victim tenant," he wrote, except the modifications themselves.
Mollema reported the issue to the Microsoft Security Response Center on 14 July 2025. According to his timeline, "Microsoft pushed a fix for the issue globally into production" on 17 July, the issue was confirmed resolved on 23 July, and CVE-2025-55241 was issued on 4 September. BleepingComputer reported that Microsoft described it as a critical privilege escalation vulnerability. "Based on Microsoft's internal telemetry, they did not detect any abuse of this vulnerability," Mollema wrote, and he published a detection query for anyone wanting to check their own tenant.
Timeline
| Date | Event |
|---|---|
| 14 July 2025 | Mollema reports the vulnerability to MSRC. |
| 17 July 2025 | Microsoft deploys a fix globally. |
| 23 July 2025 | MSRC confirms the issue is resolved. |
| 4 September 2025 | CVE-2025-55241 is issued. |
| 17 September 2025 | Mollema publishes the technical details. |
How it happened: the identity attack path
- Request an Actor token. In a tenant they control, the attacker obtains an Actor token for the Azure AD Graph.
- Find the target. The victim's tenant ID is looked up from its domain; a user's netId is brute-forced or read from a guest account.
- Craft an impersonation token. An unsigned token wraps the Actor token with the victim tenant and netId.
- Escalate to Global Admin. The attacker lists Global Admins and impersonates one.
- Take over. Any read or write action is possible over the Azure AD Graph, with logs only for the changes made.
Impact
- Potential: access to users, groups, roles, policies, applications, service principals, devices and BitLocker keys in any tenant, and full takeover through Global Admin impersonation.
- Detection: no logs for token issuance or read access; only modifications would appear.
- Actual: no abuse detected by Microsoft.
What this means for NHI governance
Actor tokens are a hidden class of non-human identity: credentials used by Microsoft services to talk to each other, with the power to impersonate anyone and none of the controls customers rely on. Tenant administrators could not see them, restrict them with Conditional Access or revoke them. The flaw that made them usable across tenants has been fixed, but the lesson is broader. Every platform has service-to-service identities that customers do not control, and their design determines how bad a single bug can be.
For customers, this is an argument for monitoring what you can: changes to privileged roles, new service principals and credentials added to applications, which were the only visible traces an attacker would have left. It is also a reminder to retire legacy APIs such as the Azure AD Graph as vendors allow. See our Active Directory and Entra ID Hardening Guide and Token and Session Security Guide.
Recommendations
- Monitor privileged changes in Entra ID. Alert on new Global Admins, new service principals and added application credentials. See the ITDR Guide.
- Run the published detection. Mollema's post includes a query to look for signs of abuse.
- Move off legacy APIs. Migrate applications from Azure AD Graph to Microsoft Graph, which has better logging. See the Active Directory and Entra ID Hardening Guide.
- Review guest accounts. Guest relationships can expose identifiers used in cross-tenant attacks. See the Access Reviews Guide.
- Ask vendors about service-to-service tokens. Understand which hidden identities can act in your tenant and how they are controlled. See the Token and Session Security Guide.
Frequently asked questions
What is CVE-2025-55241?
A critical Entra ID vulnerability in which the legacy Azure AD Graph API accepted Actor tokens from other tenants, letting an attacker impersonate any user, including Global Admins, in any tenant. Microsoft fixed it in July 2025.
What are Actor tokens?
Undocumented tokens used by Microsoft services for service-to-service communication, which let a service impersonate users for 24 hours. They were not logged when issued, not subject to Conditional Access and could not be revoked.
Was CVE-2025-55241 exploited?
Microsoft's telemetry did not detect any abuse, according to the researcher.
Related NHI Mgmt Group resources
Azure Key Vault Role Secrets Exposure · Microsoft Azure Key Breach (Storm-0558) · Active Directory and Entra ID Hardening Guide · Token and Session Security Guide · ITDR Guide
How NHI Mgmt Group can help
Cloud identity platforms rely on service identities customers never see. We help teams monitor the privileged changes that reveal their misuse and retire the legacy paths that make them dangerous. See our NHI and AI agent security training.
References
- Dirk-jan Mollema: One Token to rule them all - obtaining Global Admin in every Entra ID tenant via Actor tokens (17 September 2025)
- BleepingComputer: Microsoft Entra ID flaw allowed hijacking any company's tenant (21 September 2025)
- SecurityWeek: All Microsoft Entra Tenants Were Exposed to Silent Compromise via Invisible Actor Tokens: Researcher (23 September 2025)