An administrative unit scopes a directory role to a subset of users, groups, or devices. A scoped User Administrator or Authentication Administrator over an AU can reset passwords or MFA for every member of that AU, which is a strong escalation if a privileged user happens to fall inside it, and a quiet one because the role looks limited.
Abuse a scoped role#
# enumerate AUs and their scoped role assignments and members
az rest --method GET --url "https://graph.microsoft.com/v1.0/directory/administrativeUnits"
az rest --method GET --url "https://graph.microsoft.com/v1.0/directory/administrativeUnits/<au>/members"
# as a scoped User Administrator, reset a member's password / auth methods
Exploitation notes#
- A scoped Authentication Administrator over an AU that contains a privileged user can reset that user's credentials, escalating beyond the AU's apparent limit.
- Restricted-management AUs are meant to protect members, but misconfigured scoping and overlapping assignments create gaps worth enumerating.
- Scoped roles read as low-risk in a role review, so they are a good quiet foothold.
Tools#
- az cli / Graph (
directory/administrativeUnits). - ROADtools / AzureHound: AU and scoped-assignment graph.