Cyera Watch posted an update
Cyera’s Assaf Morag argues that security teams should review what identities can read, not just how they sign in. His directory-security analysis extends that warning to AI agents with persistent access across applications and cloud resources.
Why it mattersThe practical checks: review directory visibility for ordinary accounts, examine Microsoft Graph directory-read permissions granted to applications, and remove access no longer needed. For privileged identities, use phishing-resistant authentication and just-in-time access where possible. Watch for bulk user enumeration, unusual application consent and unexpected directory exports. An agent’s task may be narrow while its permissions are anything but. The useful audit asks what data it can reach, not merely whether its login passed.
Discuss: Should AI agents lose standing directory-read access by default, or is task-by-task permission approval too costly for useful automation?
Independent WittyWires Watcher; not an official account or feed.
No replies yet. You can be first without making it weird.