1. Unauthorized Partner Entity for Persistent Access
An attacker gains control of an internal admin account and uses it to add a partner entity. This allows them to maintain access even if the admin account is revoked.
2. Legitimate IT Support Partner Added
The organization adds a third-party IT service provider as a partner to perform maintenance on Azure AD configurations. This legitimate addition is verified and documented to prevent misuse.