A misconfigured role scope in Microsoft Entra Agent ID allowed low-privilege administrators to hijack service principals across a tenant.
Identity is the perimeter. Audit Entra role assignments, restrict Application Administrator scope, and enable Conditional Access on service principal sign-ins.
