Skip to content

Microsoft.Authorization/roleAssignments/write

Azure

Microsoft.Authorization/roleAssignments/write

service: Azure - Authorization
techniques:

Event

Microsoft.Authorization/roleAssignments/write records an Azure RBAC role-assignment write. Interpret the assigned role, receiving principal, and scope together to understand the access granted. Azure resource roles are distinct from Microsoft Entra directory roles. Role assignment concepts.

Security Context

A new role assignment can extend access or preserve it through a different principal. A broad scope and a privileged role increase the potential impact, but the actual access also depends on applicable conditions and restrictions.

Legitimate uses: application deployment, onboarding, and an approved access change. Confirm both the change requester and the identity receiving access; these are different entities.

Mapping rationale: an unauthorized additional cloud role can support persistence or privilege escalation. A role-assignment request must succeed before treating the requested grant as completed.

Log Source

Use the Administrative category of the Azure Activity Log. Subscription activity is collected automatically and retained for 90 days. For central querying or longer retention, export that category through a subscription diagnostic setting; Log Analytics stores it in AzureActivity. Collection and retention.

The sample below uses the Activity Log JSON shape. Exported records and Log Analytics columns differ. A write can have multiple lifecycle records; correlate them and inspect the final status. Optional properties content varies, so request and response bodies are not guaranteed. Event schema.

Key Fields

FieldInvestigation use
caller and identity claimsIdentify who performed the write.
operationName.value and status.valueMatch the operation and distinguish success from a start or failure.
resourceIdIdentify the role-assignment resource; it is not the receiving principal’s ID.
correlationId and operationIdJoin related records and operation lifecycle events.
properties.requestbody / properties.responseBodyIf present, parse the JSON strings for principalId, roleDefinitionId, and scope. Otherwise retrieve the assignment.
httpRequest.clientIpAddress and eventTimestampEstablish origin and timing when available.

What to Investigate

  1. Confirm a successful outcome, then resolve the role definition and receiving principal. Avoid attributing the grant to the caller as though they were necessarily the recipient.
  2. Determine the assignment scope and inherited reach. Check whether the intended access was subscription-wide, resource-group-wide, or limited to one resource.
  3. Validate the grant against the deployment or approval record. For a service principal, establish who controls its credentials and whether it subsequently used the access.
  4. Correlate later resource operations and any role-assignment deletion. A later removal limits duration but does not establish that no activity occurred while the grant existed.

Sample Event

Synthetic scenario — suspicious privilege grant. A compromised Draco identity assigns Owner at the production subscription scope to a service principal. The fictional investigation identifies that principal as BoggartImpersonator; the log itself provides its object ID. This scenario assumes the attacker also controls that principal. The illustrative request and response bodies may be absent in real records.

{
"authorization": {
"action": "Microsoft.Authorization/roleAssignments/write",
"scope": "/subscriptions/20000000-0000-4000-8000-000000000001/providers/Microsoft.Authorization/roleAssignments/60000000-0000-4000-8000-000010000000"
},
"caller": "draco@fantasticlogs.cloud",
"channels": "Operation",
"claims": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/10000000-0000-4000-8000-000000000001/",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"ipaddr": "203.0.113.66",
"name": "Draco Malfoy",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "30000000-0000-4000-8000-001010011010",
"http://schemas.microsoft.com/identity/claims/tenantid": "10000000-0000-4000-8000-000000000001",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "draco@fantasticlogs.cloud",
"http://schemas.microsoft.com/identity/claims/wids": "e8611ab8-c189-46e8-94e1-60213ab1f814"
},
"correlationId": "90000000-0000-4000-8000-000010000000",
"description": "",
"eventDataId": "90000000-0000-4000-8000-000010000001",
"eventName": {
"value": "EndRequest",
"localizedValue": "End request"
},
"category": {
"value": "Administrative",
"localizedValue": "Administrative"
},
"eventTimestamp": "2026-04-15T20:48:42.5172938Z",
"id": "/subscriptions/20000000-0000-4000-8000-000000000001/providers/Microsoft.Authorization/roleAssignments/60000000-0000-4000-8000-000010000000/events/90000000-0000-4000-8000-000010000001/ticks/639118829225172938",
"level": "Informational",
"operationId": "90000000-0000-4000-8000-000010000010",
"operationName": {
"value": "Microsoft.Authorization/roleAssignments/write",
"localizedValue": "Create role assignment"
},
"resourceGroupName": "",
"resourceProviderName": {
"value": "Microsoft.Authorization",
"localizedValue": "Microsoft.Authorization"
},
"resourceType": {
"value": "Microsoft.Authorization/roleAssignments",
"localizedValue": "Microsoft.Authorization/roleAssignments"
},
"resourceId": "/subscriptions/20000000-0000-4000-8000-000000000001/providers/Microsoft.Authorization/roleAssignments/60000000-0000-4000-8000-000010000000",
"status": {
"value": "Succeeded",
"localizedValue": "Succeeded"
},
"subStatus": {
"value": "Created",
"localizedValue": "Created (HTTP Status Code: 201)"
},
"submissionTimestamp": "2026-04-15T20:48:43.0184272Z",
"subscriptionId": "20000000-0000-4000-8000-000000000001",
"tenantId": "10000000-0000-4000-8000-000000000001",
"properties": {
"statusCode": "Created",
"serviceRequestId": null,
"responseBody": "{\"properties\":{\"roleDefinitionId\":\"/subscriptions/20000000-0000-4000-8000-000000000001/providers/Microsoft.Authorization/roleDefinitions/8e3af657-a8ff-443c-a75c-2fe8c4bcb635\",\"principalId\":\"40000000-0000-4000-8000-001010011011\",\"principalType\":\"ServicePrincipal\",\"scope\":\"/subscriptions/20000000-0000-4000-8000-000000000001\",\"createdOn\":\"2026-04-15T20:48:42.5172938Z\",\"updatedOn\":\"2026-04-15T20:48:42.5172938Z\",\"createdBy\":\"30000000-0000-4000-8000-001010011010\",\"updatedBy\":\"30000000-0000-4000-8000-001010011010\"},\"id\":\"/subscriptions/20000000-0000-4000-8000-000000000001/providers/Microsoft.Authorization/roleAssignments/60000000-0000-4000-8000-000010000000\",\"type\":\"Microsoft.Authorization/roleAssignments\",\"name\":\"60000000-0000-4000-8000-000010000000\"}",
"requestbody": "{\"properties\":{\"roleDefinitionId\":\"/subscriptions/20000000-0000-4000-8000-000000000001/providers/Microsoft.Authorization/roleDefinitions/8e3af657-a8ff-443c-a75c-2fe8c4bcb635\",\"principalId\":\"40000000-0000-4000-8000-001010011011\",\"principalType\":\"ServicePrincipal\"}}",
"eventCategory": "Administrative",
"entity": "/subscriptions/20000000-0000-4000-8000-000000000001/providers/Microsoft.Authorization/roleAssignments/60000000-0000-4000-8000-000010000000",
"message": "Microsoft.Authorization/roleAssignments/write",
"hierarchy": "10000000-0000-4000-8000-000000000001/20000000-0000-4000-8000-000000000001"
},
"relatedEvents": [],
"httpRequest": {
"clientRequestId": "90000000-0000-4000-8000-000010000011",
"clientIpAddress": "203.0.113.66",
"method": "PUT",
"url": "https://management.azure.com/subscriptions/20000000-0000-4000-8000-000000000001/providers/Microsoft.Authorization/roleAssignments/60000000-0000-4000-8000-000010000000?api-version=2022-04-01"
},
"identity": null
}

Sources

MITRE ATT&CK Mapping

Tactics: Privilege Escalation Persistence

Techniques:
  • T1098.003 — Additional Cloud Roles — An adversary may add additional roles or permissions to an adversary-controlled cloud account to maintain persistent access to a tenant. For example, adversaries may update IAM policies in cloud-based environments or add a new global administrator in Office 365 environments. With sufficient permi...
Documentation reviewed: September 28, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.