Legacy tokens and Global Admin impersonation in Entra ID: real surface, abuse, and operational control
Legacy tokens (including “actor” patterns in S2S flows) and the use of obsolete APIs such as Azure AD Graph have been a dangerous combination: they enable privileged operations without going through the same guardrails we now expect (MFA and Conditional Access). This article breaks down how Global Admin impersonation materializes in Entra ID, what signals to look for, and how to run it in practice to close the gap.