Azure authorization is Azure RBAC: role assignments bind a principal to a role at a scope (management group, subscription, resource group, or resource). Attacks here are about turning a write over the authorization plane, or control of a resource that carries a managed identity, into a higher role. This is the Azure resource plane only; tenant and directory attacks (Entra roles, users, applications) live under Entra ID in the Directory area.
The core moves are writing a role assignment to grant yourself Owner, crafting a custom role with a wildcard action, flipping on elevateAccess to seize User Access Administrator at the root, and attaching or borrowing a privileged managed identity to mint its token.
What folds in here#
- Enumeration: mapping role assignments, custom roles, and managed identities with Resource Graph, az cli, and ROADtools.
- Privilege escalation: role-assignment and custom-role writes, elevate-access, managed-identity assignment, and privileged deployments.
- Managed identities: system- and user-assigned identities as the token source behind most Azure escalation.
- PIM: activating eligible privileged roles through Privileged Identity Management.
Managed-identity token retrieval from the metadata endpoint is a credential technique and lives under credentials; this surface is about obtaining and escalating the role itself.