Alert icon Keyboard navigation enabled.
Alert icon TAB or Shift+TAB to navigate across. Down ↓ to open menu. ESC to close menu.
Alert icon Down ↓ to select section. Right → to activate. Up ↑ / Down ↓ / Tab to traverse all. ESC to exit.
BeyondTrust
Skip to content Use space or enter to skip.

What can we help you find today?

Instant Results
  • Website Results
  • Technical Documentation

Filter Options

Focus your search

Filtering by

Your recent searches:

Contact Us Chat with Sales Get Support
  • English
  • Deutsch
  • français
  • español
  • 한국어
  • português

Info icon Announcement: 2026 KuppingerCole PAM Leadership Compass: BeyondTrust recognized as an Overall Leader and top Product Leader among 36 evaluated vendors. Access the Report

  • Home
  • Resources
  • Webinars
  • How Entra Guest Users Can Exploit Microsoft Billing Permissions for Stealth Lateral Movement current page
Link copied

How Entra Guest Users Can Exploit Microsoft Billing Permissions for Stealth Lateral Movement

with Simon Maxwell-Stewart, Staff Security Researcher
Webinars default
How Entra Guest Users Can Exploit Microsoft Billing Permissions for Stealth Lateral Movement

Get Instant Access to this Content

Learn more about how to secure your business from threats in places you didn't even know existed.

About the Session

White chain icon to symbolize the ability to copy a link
Link copied
Check mark to visually show text has been copied

Inviting external guest users is a common and useful practice for collaboration with external partners, but BeyondTrust researchers discovered that Entra guest users with the right billing roles can create subscriptions and become Owners—without any explicit permissions in the target tenant. This stealthy lateral movement tactic allows a guest user to gain a foothold in an environment where they should only have limited access.

In this webinar, Simon Maxwell-Stewart, Sr Security Researcher at BeyondTrust, breaks down:

  • How little-known Microsoft Billing permissions can be misused by Entra guest users to create subscriptions in external tenants where they hold no direct privileges.
  • How attackers can exploit this unexpected access to achieve unauthorized reconnaissance and persistence in the defender’s Entra ID.
  • How some of these methods could lead to privilege escalation in certain scenarios.

Watch as we walk through real-world abuse paths, explore why this gap in access control is so dangerous, and outline what defenders need to know now.

Act Now! Get a Red-Team Assessment of your Identity Infrastructure. Request a FREE Identity Security Risk Assessment and get a snapshot of your identity security risks at no cost or obligation.

Meet the Speakers

White chain icon to symbolize the ability to copy a link
Link copied
Check mark to visually show text has been copied
Simon Maxwell-Stewart
Simon Maxwell-Stewart
Staff Security Researcher
Simon Maxwell-Stewart is a University of Oxford physics graduate with over a decade of experience in the big data environment. Before joining BeyondTrust, he worked as a Lead Data Scientist in healthcare, and successfully brought multiple machine lea ... read more

Simon Maxwell-Stewart is a University of Oxford physics graduate with over a decade of experience in the big data environment. Before joining BeyondTrust, he worked as a Lead Data Scientist in healthcare, and successfully brought multiple machine learning projects into production. Now working as a "resident graph nerd" on BeyondTrust's security research team, Simon applies his expertise in graph analysis to help drive identity security innovation.

Simon Maxwell-Stewart is a University of Oxford physics graduate with over a decade of experience in the big data environment. Before joining BeyondTrust, he worked as a Lead Data Scientist in healthcare, and successfully brought multiple machine lea ... read more
Simon Maxwell-Stewart
Staff Security Researcher

Simon Maxwell-Stewart is a University of Oxford physics graduate with over a decade of experience in the big data environment. Before joining BeyondTrust, he worked as a Lead Data Scientist in healthcare, and successfully brought multiple machine learning projects into production. Now working as a "resident graph nerd" on BeyondTrust's security research team, Simon applies his expertise in graph analysis to help drive identity security innovation.

×

Recommended Resources

White chain icon to symbolize the ability to copy a link
Link copied
Check mark to visually show text has been copied
Videos
Identity Security Insights® Assessment
Research
Buyer’s Guide for Complete Privileged Access Management (PAM)
Research
2025 Microsoft Vulnerabilities Report
Blog
When Clickbait Goes Bad – How to Protect your Identity & Business from Clickbait Phishing Scams
Blog
Restless Guests: The True Entra B2B Guest Threat Model
Blog
How to Detect Session Hijacking Before It’s Too Late: A Data Science & Behavioral Modeling Approach
Podcasts
Ep. 80 – Vampire Satellites, Stolen Wine & the Shamoon Cyberattack // Chris Kubecka
Podcasts
Ep. 79 - Hacking Rifles and Protecting Reporters // Runa Sandvik
Podcasts
Ep.78 - Champagne at 2AM: The International Zotob Takedown // Kymberlee Price
Latest
  • The Ghost in the Machine (Securing Non-Human Identities)
    Jun 18, 2026 The Ghost in the Machine (Securing Non-Human Identities)
    Webinar
Related
  • Don’t Buy a Breach: Securing Identity in M&A from Due Diligence to Day One 
    Jan 29, 2026 Don’t Buy a Breach: Securing Identity in M&A from Due Diligence to Day One 
    On-demand we...
    47m
Share this Article
  • Link
Relevant Tags
  • AI And Quantum Threats
  • Cybersecurity Innovations
  • Cybersecurity Journey
  • Cybersecurity Practices
  • Cybersecurity Trends
  • Key Forecasts2025
  • Leading Trend Predictions
  • Meet The Speakers
  • Paths To Privilege
  • Predictions2025

Keep up with BeyondTrust

Customer Support Get Started
  • LinkedIn
  • X
  • Facebook
  • Instagram
  • Add BeyondTrust as a preferred source on Google
  • Privacy
  • Security
  • Manage Cookies
  • Do Not Sell My Data
  • WEEE Compliance

Copyright © 2003 — 2026 BeyondTrust Corporation. All rights reserved. Other trademarks identified on this page are owned by their respective owners. BeyondTrust Corporation is not a chartered bank or trust company, or depository institution. It is not authorized to accept deposits or trust accounts and is not licensed or regulated by any state or federal banking authority.

Prefers reduced motion setting detected. Animations will now be reduced as a result.