Skip to content

Microsoft.ManagedIdentity/userAssignedIdentities/assign/action

Azure

Microsoft.ManagedIdentity/userAssignedIdentities/assign/action

service: Azure - Managed Identity
techniques:

Event

This is an RBAC assignment permission on the identity, not a standalone VM assignment endpoint. Attaching an identity to a VM also requires write access to the VM and changes its top-level identity configuration. Assignment makes the identity available to the workload; it does not create new role grants on other resources.

Security Context

Attaching a more privileged identity to an attacker-controlled workload can support account manipulation (T1098), if the workload can obtain and use its tokens. The identity name alone does not establish its grants, workload control, or successful token use.

Log Source

The assign/action label is an authorization permission. Do not assume every attachment emits a separate Activity Log record under that name. Inspect the target provider’s write operation (for a VM, Microsoft.Compute/virtualMachines/write) and the actual identity configuration. This sample deliberately shows API configuration rather than an unverified audit event.

Key Fields

FieldInvestigation value
method, urlIllustrative target-resource PATCH endpoint, not a logged event wrapper.
body.identity.typeUserAssigned in this example; preserve other identities when assessing real changes.
body.identity.userAssignedIdentitiesAttached identity resource IDs; resolve their effective grants separately.

What to Investigate

  1. Confirm the recorded outcome and compare actor, target, and timing with the approved workflow.
  2. Verify both resource-write and identity-assignment authority and compare the VM’s previous/new identity configuration.
  3. Resolve the identity’s service-principal ID and actual role assignments, scopes, and access restrictions.
  4. Correlate resource-write records, managed-identity sign-ins where available, and target-service activity before asserting privilege escalation.

Sample Event

Synthetic scenario. This is an illustrative VM PATCH request, not a claimed assign/action Activity Log record. It attaches an existing identity using the documented top-level identity shape; no response, token request, or effective grant is shown.

Exact field presence, payload nesting, identity/session details, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not prove intent or downstream activity.

{
"method": "PATCH",
"url": "https://management.azure.com/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-fantasticlogs-prod/providers/Microsoft.Compute/virtualMachines/vm-demiguise-infer-001?api-version=2024-03-01",
"body": {
"identity": {
"type": "UserAssigned",
"userAssignedIdentities": {
"/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-fantasticlogs-prod/providers/Microsoft.ManagedIdentity/userAssignedIdentities/umi-graphorn-admin": {}
}
}
}
}

Sources

MITRE ATT&CK Mapping

Tactics: Privilege Escalation Persistence

Techniques:
  • T1098 — Account Manipulation — Adversaries may manipulate accounts to maintain and/or elevate access to victim systems. Account manipulation may consist of any action that preserves or modifies adversary access to a compromised account, such as modifying credentials or permission groups. These actions could also include accoun...
Documentation reviewed: October 5, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.