Executive Summary
In May 2026, a security incident involving Microsoft Entra Agent ID's assistive agents was identified. An AI agent, operating under the On-Behalf-Of (OBO) authentication flow, sent a suspicious email with the subject 'Here is your invoice' from matt@ContosoCorp.onmicrosoft.com to an external recipient. The email originated from IP address 51.3.97.221, utilizing the Microsoft Graph beta API. This activity raised concerns about potential misuse of delegated permissions granted to AI agents, highlighting vulnerabilities in the OBO flow that could be exploited for unauthorized actions.
The incident underscores the growing security challenges associated with AI agents in enterprise environments. As organizations increasingly integrate AI-driven workflows, ensuring robust identity and access management for these agents becomes critical. This event serves as a reminder of the importance of monitoring AI agent activities and implementing stringent controls to prevent unauthorized access and actions.
Why This Matters Now
The rapid adoption of AI agents in business processes introduces new security risks, particularly concerning identity and access management. This incident highlights the urgency for organizations to implement comprehensive monitoring and control mechanisms to safeguard against potential misuse of AI agents.
Attack Path Analysis
An attacker exploited the On-Behalf-Of (OBO) flow in Microsoft Entra Agent ID to gain unauthorized access, escalated privileges by obtaining delegated permissions, moved laterally by leveraging the agent's access to send emails, established command and control through the compromised agent, exfiltrated data via unauthorized email communications, and impacted the organization by sending malicious emails on behalf of a legitimate user.
Kill Chain Progression
Initial Compromise
Description
The attacker exploited the On-Behalf-Of (OBO) flow in Microsoft Entra Agent ID to gain unauthorized access.
MITRE ATT&CK® Techniques
Valid Accounts
Brute Force
Application Layer Protocol
Phishing
Software Deployment Tools
Account Manipulation
Use Alternate Authentication Material
Cloud Accounts
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Ensure that security policies and operational procedures for managing user accounts are documented, in use, and known to all affected parties.
Control ID: 6.4.1
NYDFS 23 NYCRR 500 – Access Privileges
Control ID: 500.07
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Identity and Access Management
Control ID: 3.1
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Information Technology/IT
Microsoft Entra Agent ID security risks expose IT sectors to AI workflow exploitation, requiring enhanced identity management and zero trust segmentation controls.
Computer Software/Engineering
AI/ML security vulnerabilities in Microsoft environments threaten software development workflows through compromised agent identities and unauthorized API access patterns.
Financial Services
Assistive AI agents acting on behalf of users create compliance risks for PCI and regulatory frameworks through potential privilege escalation attacks.
Computer/Network Security
Cybersecurity firms must enhance threat detection capabilities for agentic authentication flows and suspicious AI workflow behaviors in cloud environments.
Sources
- Investigating suspicious AI workflows in Microsoft Entra Agent ID: Assistive agentshttps://redcanary.com/blog/threat-detection/entra-id-ai-workflows-assistive-agents/Verified
- What is Microsoft Entra Agent ID?https://learn.microsoft.com/en-us/entra/agent-id/what-is-microsoft-entra-agent-idVerified
- Authorization in Microsoft Entra Agent IDhttps://learn.microsoft.com/en-us/entra/agent-id/authorization-agent-idVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it could likely limit the attacker's ability to exploit implicit trust within cloud environments, thereby reducing the potential blast radius of such breaches.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The attacker's unauthorized access may have been constrained, reducing the likelihood of exploiting implicit trust within the cloud environment.
Control: Zero Trust Segmentation
Mitigation: The attacker's ability to escalate privileges could have been limited, reducing the scope of accessible resources.
Control: East-West Traffic Security
Mitigation: The attacker's lateral movement within the network could have been restricted, limiting unauthorized communications.
Control: Multicloud Visibility & Control
Mitigation: The attacker's command and control channels may have been detected and disrupted, reducing their ability to orchestrate further actions.
Control: Egress Security & Policy Enforcement
Mitigation: The attacker's data exfiltration attempts could have been blocked, limiting unauthorized data transfers.
The attacker's ability to cause reputational damage could have been mitigated, reducing the overall impact of the incident.
Impact at a Glance
Affected Business Functions
- Email Communication
- Customer Support
- Sales Operations
Estimated downtime: 1 days
Estimated loss: $5,000
Potential exposure of sensitive customer information due to unauthorized emails sent by compromised AI agents.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to enforce least privilege access and prevent unauthorized agent actions.
- • Utilize Multicloud Visibility & Control to monitor agent activities and detect anomalies.
- • Apply Egress Security & Policy Enforcement to restrict unauthorized outbound communications.
- • Deploy Threat Detection & Anomaly Response systems to identify and respond to suspicious agent behaviors.
- • Regularly audit agent permissions and access controls to ensure compliance with security policies.



