Privilege escalation

Azure escalation is an authorization-plane problem. A principal that can write the RBAC graph, or that controls a resource carrying a managed identity, promotes itself without touching a host. The paths below are the Azure resource-plane equivalents of the AWS IAM catalog, grounded in the NetSPI MicroBurst and SpecterOps BARK research.

The paths#

  • Role assignment write: Microsoft.Authorization/roleAssignments/write to grant yourself Owner or Contributor at any scope.
  • Custom role definition: roleDefinitions/write to craft a role with wildcard actions, then self-assign it.
  • Elevate access: toggling User Access Administrator at the root scope to reach every subscription in the tenant.
  • Managed identity assignment: attaching a privileged managed identity to a resource you control, then minting its token.
  • Deployment template: an ARM deployment or deploymentScripts resource that runs as a privileged identity.

Choosing a path#

A roleAssignments/write is the most direct lever when you hold it. Where you do not, control of a resource that already carries a privileged managed identity (a VM, a Function, an Automation Account) is usually the way up: borrow the identity through managed identities and the compute surface. BARK enumerates which of these the current principal can reach.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more