A significant vulnerability in Microsoft’s Azure and Entra ID systems that allows external guest users to exploit billing permissions to gain unauthorized access and escalate privileges within target organizations.
The issue stems from little-known Microsoft billing permissions that can be misused by guest accounts to create subscriptions in external tenants where they hold no direct administrative privileges, potentially compromising organizational security boundaries.
The vulnerability exploits the intersection between Azure’s billing system and Entra ID’s guest access model.
When organizations invite external users as guests for collaboration, these accounts typically receive limited privileges to reduce security risks.
However, researchers discovered that guest users with Enterprise Agreement (EA) or Microsoft Customer Agreement (MCA) billing roles can create and transfer Azure subscriptions into any tenant where they maintain guest access.
The attack works because billing roles exist separately from Entra directory permissions, operating at the billing account level rather than within the directory structure.
Users with roles such as Enterprise Administrator, Account Owner, Billing Account Owner, or Azure Subscription Creator can leverage these permissions to create subscriptions in external tenants, automatically receiving Owner-level access to these new subscriptions.
This capability extends even to attackers who create their own Azure tenant using a free trial, as the signup process automatically grants billing account owner permissions.
Microsoft Entra Vulnerability
Once attackers create a subscription within a target organization’s tenant, they can perform several malicious activities that would normally be impossible for unprivileged guest accounts.
The subscription ownership grants them ability to enumerate high-value administrative accounts by viewing inherited role assignments from the root management group level, exposing names and user principal names of privileged users for targeted attacks.
Attackers can also weaken security by modifying or disabling Azure policies that apply to their subscription, effectively muting security alerts and reducing visibility from monitoring tools.
More concerning, they can create User-Managed Identities within their subscription, which introduces new service principals into the shared Entra ID directory.
These managed identities can serve as persistent backdoors, especially when attackers add federated credentials that allow external authentication even after the original guest account is removed.
Additionally, attackers can register Azure-joined devices by creating virtual machines with Azure AD-based Windows Login extensions.
These devices can potentially abuse conditional access policies and dynamic group memberships, providing unauthorized access to trusted organizational resources.
Security Implications
When BeyondTrust reported the issue to Microsoft in October 2024, the company confirmed this represents expected behavior rather than a security vulnerability.
Microsoft explained the functionality was designed as a requested feature to allow guest accounts to create subscriptions across multiple tenants.
They emphasized that guests remain responsible for billing costs and noted that subscriptions act as security boundaries to limit broader tenant impact.
Microsoft has provided subscription policies that organizations can enable to prevent guests from transferring subscriptions into their tenant, though this protection is not enabled by default.
BeyondTrust recommends organizations immediately audit guest accounts, enable restrictive subscription policies, monitor for unexpected guest-created subscriptions, and implement enhanced device access controls to mitigate these risks.
Find this Story Interesting! Follow us on LinkedIn and X to Get More Instant Updates.
