A tenant Global Administrator (an Entra role) can flip a single switch that grants the User Access Administrator role at the root scope (/), above every management group and subscription. Once elevated, the principal can read and write role assignments across the entire tenant, which is the bridge from directory control to full resource-plane control.
Toggling it#
# requires the Global Administrator directory role; grants UAA at "/"
az rest --method post \
--url "https://management.azure.com/providers/Microsoft.Authorization/elevateAccess?api-version=2016-07-01"
# now assignable at the root scope
az role assignment create --assignee <object-id> --role Owner --scope "/"
Exploitation notes#
- This is the one place the Entra directory plane and the Azure resource plane meet: it takes a directory role (Global Admin) to perform, and yields resource-plane power everywhere. The directory-side attacks that reach Global Admin live under Entra ID in the Directory area.
- The elevation is logged and the UAA-at-root assignment is visible to anyone auditing root-scope RBAC; it is loud but total.
- Remove the root assignment afterwards to reduce the footprint while keeping any scoped Owner grants you made.
Tools#
- az cli (
az restfor the elevateAccess POST). - MicroBurst / BARK: automate the elevate-then-assign sequence.