Skip to finding
important · Identity

Read-only Entra roles could obtain Connect Health agent secrets and write hybrid-monitoring telemetry.

Affects

Microsoft Entra Connect Health, the Microsoft-hosted monitoring service for on-premises Entra Connect Sync, AD FS, and AD DS agents.

Global Reader—and Security Reader for the demonstrated AD FS path—could invoke credentials/read, receive the live AgentKey and disconnect the legitimate agent when the read rotated that key.

Detail and 1 source

The stolen key minted an agent bearer token and exposed write-capable Event Hub and Blob credentials for forged telemetry or monitoring disruption.

The report found no broader Graph, Key Vault, ARM or storage-read pivot, and remediation remained partial without complete revocation.

Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Friday, September 4, 2026