Skip to content

Add Role Definition (Azure RBAC)

Azure

Add Role Definition (Azure RBAC)

service: Azure - Authorization
techniques:

Event

Creates a custom Azure RBAC permission definition. Actions and DataActions cover different permission planes; NotActions/NotDataActions subtract from this role’s grants and are not deny assignments. AssignableScopes controls where the role may be assigned; actual role-assignment scopes determine where a principal receives access.

Security Context

A malicious definition may prepare additional cloud-role access (contextual T1098.003), but definition creation does not assign it to anyone. Wildcard snapshot permissions warrant review; they do not establish permission over every source disk, successful snapshot creation, or exported contents. Approved role maintenance uses the same operation.

Log Source

Azure Activity Log, Administrative category, with operationName.value: Microsoft.Authorization/roleDefinitions/write. This page’s title is a catalog label for the ARM operation, not the similarly named Entra RoleManagement audit activity. Creation and update share the same operation name; use result, resource history, and prior state to distinguish them. Request/response bodies are not guaranteed in Activity Log exports.

Key Fields

FieldInvestigation value
operationName.value, resourceIdARM role-definition write operation and definition ID.
properties.requestbody, properties.responseBodyDefinition if included; payload presence is not guaranteed.
status, correlationId, operationIdRecorded result and related operation records.

What to Investigate

  1. Confirm the recorded outcome and match the initiating identity, target, and timing to an approved change.
  2. Recover the prior and resulting definitions and compare all permission arrays and assignment eligibility scopes.
  3. Enumerate actual role assignments, their scopes, conditions, and applicable deny assignments; do not infer effective access from the role name.
  4. Correlate role assignments and subsequent resource operations before claiming escalation or data theft.

Sample Event

Synthetic scenario. BackupReader includes a snapshot-action wildcard despite its read-only description. The record does not establish any assignee, source-disk authorization, or snapshot/export operation.

Exact field presence, target ordering, modified-property names, and payload serialization remain unverified against captured logs. Treat these examples as illustrations, not guaranteed schemas or complete change histories.

{
"authorization": {
"action": "Microsoft.Authorization/roleDefinitions/write",
"scope": "/subscriptions/20000000-0000-4000-8000-000000000001/providers/Microsoft.Authorization/roleDefinitions/50000000-0000-4000-8000-000001101001"
},
"caller": "draco@fantasticlogs.cloud",
"channels": "Operation",
"claims": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/10000000-0000-4000-8000-000000000001/",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"ipaddr": "203.0.113.66",
"name": "Draco Malfoy",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "30000000-0000-4000-8000-001010011010",
"http://schemas.microsoft.com/identity/claims/tenantid": "10000000-0000-4000-8000-000000000001",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "draco@fantasticlogs.cloud",
"http://schemas.microsoft.com/identity/claims/wids": "e8611ab8-c189-46e8-94e1-60213ab1f814"
},
"correlationId": "90000000-0000-4000-8000-000001101001",
"description": "",
"eventDataId": "90000000-0000-4000-8000-000001101010",
"eventName": {
"value": "EndRequest",
"localizedValue": "End request"
},
"category": {
"value": "Administrative",
"localizedValue": "Administrative"
},
"eventTimestamp": "2026-04-15T19:02:14.7382194Z",
"level": "Informational",
"operationId": "90000000-0000-4000-8000-000001101011",
"operationName": {
"value": "Microsoft.Authorization/roleDefinitions/write",
"localizedValue": "Create role definition"
},
"resourceGroupName": "",
"resourceProviderName": {
"value": "Microsoft.Authorization",
"localizedValue": "Microsoft.Authorization"
},
"resourceType": {
"value": "Microsoft.Authorization/roleDefinitions",
"localizedValue": "Microsoft.Authorization/roleDefinitions"
},
"resourceId": "/subscriptions/20000000-0000-4000-8000-000000000001/providers/Microsoft.Authorization/roleDefinitions/50000000-0000-4000-8000-000001101001",
"status": {
"value": "Succeeded",
"localizedValue": "Succeeded"
},
"subStatus": {
"value": "Created",
"localizedValue": "Created (HTTP Status Code: 201)"
},
"submissionTimestamp": "2026-04-15T19:02:15.4192835Z",
"subscriptionId": "20000000-0000-4000-8000-000000000001",
"tenantId": "10000000-0000-4000-8000-000000000001",
"properties": {
"statusCode": "Created",
"serviceRequestId": null,
"responseBody": "{\"properties\":{\"roleName\":\"BackupReader\",\"description\":\"Read-only backup operator role\",\"assignableScopes\":[\"/subscriptions/20000000-0000-4000-8000-000000000001\"],\"permissions\":[{\"actions\":[\"Microsoft.Compute/disks/read\",\"Microsoft.Compute/snapshots/*\",\"Microsoft.Storage/storageAccounts/read\"],\"notActions\":[],\"dataActions\":[],\"notDataActions\":[]}],\"createdOn\":\"2026-04-15T19:02:14.6173821Z\",\"updatedOn\":\"2026-04-15T19:02:14.6173821Z\",\"createdBy\":\"30000000-0000-4000-8000-001010011010\",\"updatedBy\":\"30000000-0000-4000-8000-001010011010\",\"roleType\":\"CustomRole\"},\"id\":\"/subscriptions/20000000-0000-4000-8000-000000000001/providers/Microsoft.Authorization/roleDefinitions/50000000-0000-4000-8000-000001101001\",\"type\":\"Microsoft.Authorization/roleDefinitions\",\"name\":\"50000000-0000-4000-8000-000001101001\"}",
"requestbody": "{\"properties\":{\"roleName\":\"BackupReader\",\"description\":\"Read-only backup operator role\",\"permissions\":[{\"actions\":[\"Microsoft.Compute/disks/read\",\"Microsoft.Compute/snapshots/*\",\"Microsoft.Storage/storageAccounts/read\"],\"notActions\":[]}],\"assignableScopes\":[\"/subscriptions/20000000-0000-4000-8000-000000000001\"],\"roleType\":\"CustomRole\"}}",
"eventCategory": "Administrative",
"entity": "/subscriptions/20000000-0000-4000-8000-000000000001/providers/Microsoft.Authorization/roleDefinitions/50000000-0000-4000-8000-000001101001",
"message": "Microsoft.Authorization/roleDefinitions/write",
"hierarchy": "10000000-0000-4000-8000-000000000001/20000000-0000-4000-8000-000000000001"
},
"relatedEvents": [],
"httpRequest": {
"clientRequestId": "90000000-0000-4000-8000-000001101100",
"clientIpAddress": "203.0.113.66",
"method": "PUT",
"url": "https://management.azure.com/subscriptions/20000000-0000-4000-8000-000000000001/providers/Microsoft.Authorization/roleDefinitions/50000000-0000-4000-8000-000001101001?api-version=2022-04-01"
},
"identity": null
}

Sources

MITRE ATT&CK Mapping

Tactics: Privilege Escalation Persistence

Techniques:
  • T1098.003 — Additional Cloud Roles — An adversary may add additional roles or permissions to an adversary-controlled cloud account to maintain persistent access to a tenant. For example, adversaries may update IAM policies in cloud-based environments or add a new global administrator in Office 365 environments. With sufficient permi...
Documentation reviewed: September 30, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.