Read-only Entra roles could obtain Connect Health agent secrets and write hybrid-monitoring telemetry.
Microsoft Entra Connect Health, the Microsoft-hosted monitoring service for on-premises Entra Connect Sync, AD FS, and AD DS agents.
Global Reader—and Security Reader for the demonstrated AD FS path—could invoke credentials/read, receive the live AgentKey and disconnect the legitimate agent when the read rotated that key.
Detail and 1 source
The stolen key minted an agent bearer token and exposed write-capable Event Hub and Blob credentials for forged telemetry or monitoring disruption.
The report found no broader Graph, Key Vault, ARM or storage-read pivot, and remediation remained partial without complete revocation.