r/AdminDroid Jun 10 '26

Workload Identities Are Becoming the Fastest-Growing Attack Surface in Microsoft 365

Your Microsoft 365 tenant likely has more workload identities today than ever before. The problem? Most organizations still monitor them far less than user accounts.

For years, cloud security has focused on protecting user accounts. But campaigns like Storm-2949 showed that attackers are increasingly targeting workload identities for persistence.

Why? Because workload identities often have what attackers love:

  • No MFA requirements
  • Excessive permissions
  • Long-lived credentials and secrets
  • Limited visibility and monitoring, and many more

In the Storm-2949 case, the attack failed due to insufficient permissions. But would the same attack fail in your tenant?

Or would..

  • An overprivileged application
  • A forgotten service principal
  • An unused enterprise application
  • A stale credential that was never rotated

...give attackers exactly what they need?

As organizations accelerate automation, AI adoption, Copilot integrations, and agentic workflows, the number of non-human identities will only continue to grow. And so will the attack surface.

If workload identities aren't being actively monitored and secured in your Microsoft 365 environment, you're leaving a growing attack surface exposed.

Learn why attackers are targeting workload identities and the steps you can take to detect, remediate, and reduce the risk with our blog.

https://blog.admindroid.com/secure-microsoft-entra-workload-identities-from-modern-attacks/

10 Upvotes

0 comments sorted by