Microsoft.Authorization/elevateAccess/action
Microsoft.Authorization/elevateAccess/action
Event
Allows a Global Administrator to obtain User Access Administrator at Azure root scope (/), covering associated subscriptions and management groups. Root scope is not the tenant root management-group resource. The role permits access management; it is not itself Owner or unrestricted data-plane access.
Security Context
Unauthorized elevation can add cloud-role privileges (T1098.003). Recovery administration is a legitimate use. It starts with Entra Global Administrator authority; it does not grant that directory role. Additional assignments may provide broader resource access.
Log Source
Azure Activity Log, Administrative category, with operationName.value: Microsoft.Authorization/elevateAccess/action. Inspect status/subStatus and related records; an accepted asynchronous request is not final resource-state evidence. Request and response bodies are optional and export-dependent. This is tenant-level Directory Activity, not necessarily part of a subscription-only export. Microsoft also documents Entra elevated-access audit records; verify collection in the tenant.
Key Fields
| Field | Investigation value |
|---|---|
caller, claims, tenantId | Requesting identity and tenant context. |
authorization.scope, subscriptionId | Tenant-level operation; an empty subscriptionId is expected in the illustrative record. |
What to Investigate
- Confirm the recorded outcome and compare actor, target, and timing with the approved workflow.
- Verify Global Administrator status/activation and the approved reason for elevation.
- Inspect the resulting User Access Administrator assignment at / and subsequent role grants.
- Verify elevated access was removed when no longer needed; deactivating PIM Global Administrator does not itself remove this separate root assignment.
Sample Event
Synthetic scenario. The sample records an elevation request by a Global Administrator. It does not show subsequent Owner assignment or resource manipulation.
Exact field presence, modified-property names, payload nesting, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not prove intent or downstream activity.
{ "authorization": { "action": "Microsoft.Authorization/elevateAccess/action", "scope": "/providers/Microsoft.Authorization" }, "caller": "draco@fantasticlogs.cloud", "channels": "Operation", "claims": { "aud": "https://management.core.windows.net/", "iss": "https://sts.windows.net/10000000-0000-4000-8000-000000000001/", "http://schemas.microsoft.com/claims/authnclassreference": "1", "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd", "appid": "00001111-aaaa-2222-bbbb-3333cccc4444", "appidacr": "0", "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "Malfoy", "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Draco", "ipaddr": "203.0.113.66", "name": "Draco Malfoy", "http://schemas.microsoft.com/identity/claims/objectidentifier": "30000000-0000-4000-8000-001010011010", "puid": "1003200000000666", "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation", "http://schemas.microsoft.com/identity/claims/tenantid": "10000000-0000-4000-8000-000000000001", "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "draco@fantasticlogs.cloud", "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "draco@fantasticlogs.cloud", "http://schemas.microsoft.com/identity/claims/wids": "62e90394-69f5-4237-9190-012177145e10", "uti": "elev666AccessUtIDSampL", "ver": "1.0" }, "correlationId": "90000000-0000-4000-8000-001010011010", "description": "", "eventDataId": "90000000-0000-4000-8000-001010011011", "eventName": { "value": "EndRequest", "localizedValue": "End request" }, "category": { "value": "Administrative", "localizedValue": "Administrative" }, "eventTimestamp": "2026-04-15T17:23:08.4715290Z", "level": "Informational", "operationId": "90000000-0000-4000-8000-001010011100", "operationName": { "value": "Microsoft.Authorization/elevateAccess/action", "localizedValue": "Assigns the caller to User Access Administrator role" }, "resourceGroupName": "", "resourceProviderName": { "value": "Microsoft.Authorization", "localizedValue": "Microsoft.Authorization" }, "resourceType": { "value": "Microsoft.Authorization", "localizedValue": "Microsoft.Authorization" }, "resourceId": "/providers/Microsoft.Authorization", "status": { "value": "Succeeded", "localizedValue": "Succeeded" }, "subStatus": { "value": "OK", "localizedValue": "OK (HTTP Status Code: 200)" }, "submissionTimestamp": "2026-04-15T17:23:09.0218742Z", "subscriptionId": "", "tenantId": "10000000-0000-4000-8000-000000000001", "properties": { "requestbody": "{}", "eventCategory": "Administrative", "entity": "/providers/Microsoft.Authorization", "message": "Microsoft.Authorization/elevateAccess/action", "hierarchy": "" }, "relatedEvents": []}Sources
MITRE ATT&CK Mapping
Tactics: Privilege Escalation
- T1098.003 — Additional Cloud Roles — An adversary may add additional roles or permissions to an adversary-controlled cloud account to maintain persistent access to a tenant. For example, adversaries may update IAM policies in cloud-based environments or add a new global administrator in Office 365 environments. With sufficient permi...