This blog reveals a novel attack path in Microsoft Entra ID (formerly Azure AD) that leverages a little-known Azure VM feature to escalate privileges from guest access to full Entra admin. By combining device identity abuse with phishing techniques to steal Primary Refresh Tokens (PRTs), attackers can bypass traditional security controls and perform stealthy lateral movement. Building on our previous Restless Guests research, we unpack each stage of the “Evil VM” attack chain and provide practical guidance for defenders to detect and mitigate these risks.