# Entra Agent ID: Inside a cross-tenant agent compromise

DevFeed: [Entra Agent ID: Inside a cross-tenant agent compromise](<https://devfeed.tech/articles/entra-agent-id-inside-a-cross-tenant-agent-compromise-8268.md>)

Original publisher: [Read original article](<https://securitylabs.datadoghq.com/articles/agent-id-inside-agent-compromise/>)

Author: Katie Knowles

Published: 2026-06-18T00:00:00Z

Content type: article

Language: en

Sources: [Datadog Security Labs](<https://devfeed.tech/sources/datadog-security-labs.md>)

Topics: [Entra ID](<https://devfeed.tech/topics/entra-id.md>), [Security](<https://devfeed.tech/topics/security.md>), [Authorization](<https://devfeed.tech/topics/authorization.md>), [incident](<https://devfeed.tech/topics/incident.md>)

Tags: [agent](<https://devfeed.tech/tags/agent.md>), [agents](<https://devfeed.tech/tags/agents.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [blog](<https://devfeed.tech/tags/blog.md>), [entra-id](<https://devfeed.tech/tags/entra-id.md>), [identity](<https://devfeed.tech/tags/identity.md>), [incident](<https://devfeed.tech/tags/incident.md>), [post](<https://devfeed.tech/tags/post.md>), [security](<https://devfeed.tech/tags/security.md>)

## AI overview

This post demonstrates how compromising a privileged agent through a third-party Entra agent blueprint can enable cross-tenant access. An attacker who controls the blueprint can add a credential and authenticate as associated agent service principals, identities, and users across Entra tenants, potentially exposing identities with different permission contexts.

## Source excerpt

Continuing our Agent ID series, this post demonstrates how a privileged agent could be compromised through its third-party blueprint. This leads to a cross-tenant incident similar to Midnight Blizzard, since an attacker with control over an agent blueprint can authenticate as any agent associated with that blueprint.