Microsoft.ManagedIdentity/userAssignedIdentities/assign/action
Microsoft.ManagedIdentity/userAssignedIdentities/assign/action
Event
This is an RBAC assignment permission on the identity, not a standalone VM assignment endpoint. Attaching an identity to a VM also requires write access to the VM and changes its top-level identity configuration. Assignment makes the identity available to the workload; it does not create new role grants on other resources.
Security Context
Attaching a more privileged identity to an attacker-controlled workload can support account manipulation (T1098), if the workload can obtain and use its tokens. The identity name alone does not establish its grants, workload control, or successful token use.
Log Source
The assign/action label is an authorization permission. Do not assume every attachment emits a separate Activity Log record under that name. Inspect the target provider’s write operation (for a VM, Microsoft.Compute/virtualMachines/write) and the actual identity configuration. This sample deliberately shows API configuration rather than an unverified audit event.
Key Fields
| Field | Investigation value |
|---|---|
method, url | Illustrative target-resource PATCH endpoint, not a logged event wrapper. |
body.identity.type | UserAssigned in this example; preserve other identities when assessing real changes. |
body.identity.userAssignedIdentities | Attached identity resource IDs; resolve their effective grants separately. |
What to Investigate
- Confirm the recorded outcome and compare actor, target, and timing with the approved workflow.
- Verify both resource-write and identity-assignment authority and compare the VM’s previous/new identity configuration.
- Resolve the identity’s service-principal ID and actual role assignments, scopes, and access restrictions.
- Correlate resource-write records, managed-identity sign-ins where available, and target-service activity before asserting privilege escalation.
Sample Event
Synthetic scenario. This is an illustrative VM PATCH request, not a claimed assign/action Activity Log record. It attaches an existing identity using the documented top-level identity shape; no response, token request, or effective grant is shown.
Exact field presence, payload nesting, identity/session details, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not prove intent or downstream activity.
{ "method": "PATCH", "url": "https://management.azure.com/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-fantasticlogs-prod/providers/Microsoft.Compute/virtualMachines/vm-demiguise-infer-001?api-version=2024-03-01", "body": { "identity": { "type": "UserAssigned", "userAssignedIdentities": { "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-fantasticlogs-prod/providers/Microsoft.ManagedIdentity/userAssignedIdentities/umi-graphorn-admin": {} } } }}Sources
MITRE ATT&CK Mapping
Tactics: Privilege Escalation Persistence
- T1098 — Account Manipulation — Adversaries may manipulate accounts to maintain and/or elevate access to victim systems. Account manipulation may consist of any action that preserves or modifies adversary access to a compromised account, such as modifying credentials or permission groups. These actions could also include accoun...