Microsoft recently patched a serious Entra ID flaw that allowed attackers to hijack any organization’s Azure/Entra ID tenant. The flaw emerged from a mix of legacy actor tokens and a vulnerability in the Azure AD Graph API. It risked full tenant takeover without detection. What the Flaw Entailed Security researcher Dirk-jan Mollema discovered that “actor…