Skip to content

Microsoft.Authorization/elevateAccess/action

Azure

Microsoft.Authorization/elevateAccess/action

service: Azure - Authorization
techniques:

Event

Allows a Global Administrator to obtain User Access Administrator at Azure root scope (/), covering associated subscriptions and management groups. Root scope is not the tenant root management-group resource. The role permits access management; it is not itself Owner or unrestricted data-plane access.

Security Context

Unauthorized elevation can add cloud-role privileges (T1098.003). Recovery administration is a legitimate use. It starts with Entra Global Administrator authority; it does not grant that directory role. Additional assignments may provide broader resource access.

Log Source

Azure Activity Log, Administrative category, with operationName.value: Microsoft.Authorization/elevateAccess/action. Inspect status/subStatus and related records; an accepted asynchronous request is not final resource-state evidence. Request and response bodies are optional and export-dependent. This is tenant-level Directory Activity, not necessarily part of a subscription-only export. Microsoft also documents Entra elevated-access audit records; verify collection in the tenant.

Key Fields

FieldInvestigation value
caller, claims, tenantIdRequesting identity and tenant context.
authorization.scope, subscriptionIdTenant-level operation; an empty subscriptionId is expected in the illustrative record.

What to Investigate

  1. Confirm the recorded outcome and compare actor, target, and timing with the approved workflow.
  2. Verify Global Administrator status/activation and the approved reason for elevation.
  3. Inspect the resulting User Access Administrator assignment at / and subsequent role grants.
  4. Verify elevated access was removed when no longer needed; deactivating PIM Global Administrator does not itself remove this separate root assignment.

Sample Event

Synthetic scenario. The sample records an elevation request by a Global Administrator. It does not show subsequent Owner assignment or resource manipulation.

Exact field presence, modified-property names, payload nesting, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not prove intent or downstream activity.

{
"authorization": {
"action": "Microsoft.Authorization/elevateAccess/action",
"scope": "/providers/Microsoft.Authorization"
},
"caller": "draco@fantasticlogs.cloud",
"channels": "Operation",
"claims": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/10000000-0000-4000-8000-000000000001/",
"http://schemas.microsoft.com/claims/authnclassreference": "1",
"http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd",
"appid": "00001111-aaaa-2222-bbbb-3333cccc4444",
"appidacr": "0",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "Malfoy",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Draco",
"ipaddr": "203.0.113.66",
"name": "Draco Malfoy",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "30000000-0000-4000-8000-001010011010",
"puid": "1003200000000666",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
"http://schemas.microsoft.com/identity/claims/tenantid": "10000000-0000-4000-8000-000000000001",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "draco@fantasticlogs.cloud",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "draco@fantasticlogs.cloud",
"http://schemas.microsoft.com/identity/claims/wids": "62e90394-69f5-4237-9190-012177145e10",
"uti": "elev666AccessUtIDSampL",
"ver": "1.0"
},
"correlationId": "90000000-0000-4000-8000-001010011010",
"description": "",
"eventDataId": "90000000-0000-4000-8000-001010011011",
"eventName": {
"value": "EndRequest",
"localizedValue": "End request"
},
"category": {
"value": "Administrative",
"localizedValue": "Administrative"
},
"eventTimestamp": "2026-04-15T17:23:08.4715290Z",
"level": "Informational",
"operationId": "90000000-0000-4000-8000-001010011100",
"operationName": {
"value": "Microsoft.Authorization/elevateAccess/action",
"localizedValue": "Assigns the caller to User Access Administrator role"
},
"resourceGroupName": "",
"resourceProviderName": {
"value": "Microsoft.Authorization",
"localizedValue": "Microsoft.Authorization"
},
"resourceType": {
"value": "Microsoft.Authorization",
"localizedValue": "Microsoft.Authorization"
},
"resourceId": "/providers/Microsoft.Authorization",
"status": {
"value": "Succeeded",
"localizedValue": "Succeeded"
},
"subStatus": {
"value": "OK",
"localizedValue": "OK (HTTP Status Code: 200)"
},
"submissionTimestamp": "2026-04-15T17:23:09.0218742Z",
"subscriptionId": "",
"tenantId": "10000000-0000-4000-8000-000000000001",
"properties": {
"requestbody": "{}",
"eventCategory": "Administrative",
"entity": "/providers/Microsoft.Authorization",
"message": "Microsoft.Authorization/elevateAccess/action",
"hierarchy": ""
},
"relatedEvents": []
}

Sources

MITRE ATT&CK Mapping

Tactics: Privilege Escalation

Techniques:
  • T1098.003 — Additional Cloud Roles — An adversary may add additional roles or permissions to an adversary-controlled cloud account to maintain persistent access to a tenant. For example, adversaries may update IAM policies in cloud-based environments or add a new global administrator in Office 365 environments. With sufficient permi...
Documentation reviewed: October 4, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.