For customers of Microsoft 365 and Azure, obtaining the role of Global Administrator (GA) is every attacker's dream - it is the Domain Administrator of the cloud. This makes Global Administrator every organizations nightmare of being owned by a threat group or hacker. Luckily, well-defined role-based access control and a strict application consent model can severely limit who gets their fingers on Global Administrator - or does it? This session walks through the research background and the discovery of unexpected authorization in Entra, allowing an Application Administrator to abuse Microsoft service principals to take the role of Global Administrator, among some other discoveries. Unique to this BlueHat session, we'll then pivot and dive into the MSRC response and resolution, directly from an MSRC researcher involved in the case. We'll explore how MSRC and the IDNA team worked to resolve a complex and layered case, provide insight into what goes on behind the scenes when researching a reported identity vulnerability, as well as additional background on the findings from the Microsoft side.