Azure escalation is an authorization-plane problem. A principal that can write the RBAC graph, or that controls a resource carrying a managed identity, promotes itself without touching a host. The paths below are the Azure resource-plane equivalents of the AWS IAM catalog, grounded in the NetSPI MicroBurst and SpecterOps BARK research.
The paths#
- Role assignment write:
Microsoft.Authorization/roleAssignments/writeto grant yourself Owner or Contributor at any scope. - Custom role definition:
roleDefinitions/writeto craft a role with wildcard actions, then self-assign it. - Elevate access: toggling User Access Administrator at the root scope to reach every subscription in the tenant.
- Managed identity assignment: attaching a privileged managed identity to a resource you control, then minting its token.
- Deployment template: an ARM deployment or deploymentScripts resource that runs as a privileged identity.
Choosing a path#
A roleAssignments/write is the most direct lever when you hold it. Where you do not, control of a resource that already carries a privileged managed identity (a VM, a Function, an Automation Account) is usually the way up: borrow the identity through managed identities and the compute surface. BARK enumerates which of these the current principal can reach.