Group ownership

A group owner can manage its membership, so owning a group means you can add yourself to it and inherit whatever it grants: application access, resource roles, or a bound directory role. Ownership is delegated casually and seldom audited, which makes it a common quiet edge into a privileged group.

Add yourself as a member#

bash
# list groups you own, then add a member
az rest --method GET --url "https://graph.microsoft.com/v1.0/me/ownedObjects"
az rest --method POST --url "https://graph.microsoft.com/v1.0/groups/<group>/members/\$ref" \
  --body '{"@odata.id":"https://graph.microsoft.com/v1.0/directoryObjects/<you>"}'

Exploitation notes#

  • Target owners of groups that back privileged app roles or that are role-assignable; membership then becomes those permissions.
  • Owners can also add a service principal you control, giving a non-interactive foothold in the group.
  • Group membership changes are visible in membership listings, so this is more durable than stealthy.

Tools#

  • az cli / Graph (groups/{id}/members/$ref).
  • AzureHound / BARK: owner-to-group edges.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more