For customers of Microsoft 365 and Azure, obtaining the role of Global Administrator (GA) is every attacker's dream – it is the Domain Administrator of the cloud. This makes Global Administrator every organization's nightmare of being owned by a threat group or hacker. Luckily, well-defined role-based access control and a strict application consent model can severely limit who gets their fingers on Global Administrator – or does it?This talk walks through the UnOAuthorized discovery that resulted in privilege elevation to Global Administrator in Entra ID (Azure AD), among other nefarious privileged actions. The research that resulted in the discovery provides interesting twists, such as the exploration of Microsoft first-party applications, their Microsoft Graph application permissions, and finding the path to Global Administrator hiding where least expected.Part conversation about the research background, part exploration of application permissions in Entra ID, this talk will walk through the entire path to privilege elevation step-by-step, as well as defense and detection of abuse.With the discovery renewing interest as to whether third-party applications are vulnerable to this finding, we will also explore how enterprises can protect themselves from crafting scenarios "by design" that lead to similar privilege elevation.