Identity

Azure authorization is Azure RBAC: role assignments bind a principal to a role at a scope (management group, subscription, resource group, or resource). Attacks here are about turning a write over the authorization plane, or control of a resource that carries a managed identity, into a higher role. This is the Azure resource plane only; tenant and directory attacks (Entra roles, users, applications) live under Entra ID in the Directory area.

The core moves are writing a role assignment to grant yourself Owner, crafting a custom role with a wildcard action, flipping on elevateAccess to seize User Access Administrator at the root, and attaching or borrowing a privileged managed identity to mint its token.

What folds in here#

  • Enumeration: mapping role assignments, custom roles, and managed identities with Resource Graph, az cli, and ROADtools.
  • Privilege escalation: role-assignment and custom-role writes, elevate-access, managed-identity assignment, and privileged deployments.
  • Managed identities: system- and user-assigned identities as the token source behind most Azure escalation.
  • PIM: activating eligible privileged roles through Privileged Identity Management.

Managed-identity token retrieval from the metadata endpoint is a credential technique and lives under credentials; this surface is about obtaining and escalating the role itself.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more