Role-assignable groups

A group created with isAssignableToRole can have directory roles assigned to it, and every member inherits those roles. So control of such a group, through ownership, dynamic membership, or a role that can edit its members, is control of the roles bound to it, potentially up to Global Administrator.

Find and join#

bash
# list role-assignable groups
az rest --method GET --url "https://graph.microsoft.com/v1.0/groups?\$filter=isAssignableToRole eq true"
# check which roles are assigned to the group, then get yourself added as a member
az rest --method GET --url "https://graph.microsoft.com/v1.0/roleManagement/directory/roleAssignments?\$filter=principalId eq '<group>'"

Exploitation notes#

  • Role-assignable groups are protected (only higher-privileged roles can manage them), but an owner set at creation or a mis-scoped manager still gets you in.
  • A single role-assignable group bound to Global Admin turns any membership edge into tenant takeover.
  • Adding a controlled service principal as a member gives a non-interactive, MFA-exempt path to the role.

Tools#

  • az cli / Graph (groups isAssignableToRole, roleAssignments).
  • AzureHound / BARK: group-to-role edges.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more