Secureworks reported that multiple Microsoft Azure Active Directory APIs exposed internal tenant information that could help attackers profile organizations and prepare follow-on attacks. The exposed data included tenant domains, licensing details, mailbox information, directory synchronization status, and in some cases technical contact information for other tenants. According to the report, both unauthenticated and authenticated API behaviors enabled access to this organizational open-source intelligence, creating opportunities for phishing, social engineering, and targeted brute-force activity against Azure AD tenants.
Microsoft later mitigated most of the exposures after responsible disclosure, with the remaining issues involving synchronization status and organizational contact information addressed by April 2022. The findings are especially relevant because Microsoft Entra tenants commonly use verified custom domains for user identities instead of default onmicrosoft.com names, making domain and tenant metadata valuable for adversaries mapping targets and identifying administrative or federated environments.

See affected versions and whether adversaries are exploiting it.
9 events from the most recent confirmed update back to the earliest known activity.
By April 12, 2022, Microsoft had reassessed and addressed the remaining issues. Synchronization status was restricted to the user's own tenant, and the admin API required administrator access and no longer returned the technical contact's name.
On January 28, 2022, Microsoft closed the cloudcheck issue as fixed, except for the remaining directory synchronization status exposure. That residual issue could still reveal synchronization configuration, operational status, last sync time, and sometimes the sync service account name.
Microsoft stated on January 12, 2022, that the organization information exposed by the admin API was expected to be shown and initially did not mitigate the issue.
On December 14, 2021, Secureworks CTU reported that an admin API used by the Microsoft 365 admin center could return partner organization details and technical contact information for any tenant.
Microsoft applied an update on December 2, 2021, to address the reported cloudcheck endpoint vulnerability. The fix did not fully eliminate the directory synchronization status exposure.
On September 23, 2021, Secureworks CTU reported that the newer cloudcheck endpoint exposed similar diagnostic information for other users and tenants through several symptoms, despite the earlier fix to the analysis endpoint.
Microsoft told Secureworks on September 22, 2021, that the analysis endpoint issue had been resolved. The fix blocked access to other users' information and invalidated AnalyzerIDs for the obsolete endpoint.
On September 7, 2021, Secureworks CTU disclosed to Microsoft that the Diagnostics API analysis endpoint allowed an authenticated user to retrieve information about arbitrary users and tenants by changing the SMTP address parameter.
Secureworks Counter Threat Unit researchers analyzed Azure Active Directory tenants in the second half of 2021 and found multiple APIs exposing organizational and tenant information useful for reconnaissance. The exposed data included tenant domains, IDs, licensing details, mailbox information, and synchronization-related details.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.