A vulnerability in Microsoft Dynamics 365 Supply Chain Visibility allowed arbitrary takeover of Azure tenants via a malicious reply URL. Clicking a link could grant an attacker directory read access or full tenant control if clicked by a Global Admin, without requiring user consent.
Affected Services
Microsoft Entra ID, Microsoft Dynamics 365 Supply Chain Visibility
Monitor for unexpected additions of users to high-privilege roles like Global Administrator. Review sign-in logs for suspicious access from unfamiliar IP addresses or locations.