Update Role Definition (Azure RBAC)
Update Role Definition (Azure RBAC)
Event
Updates an existing custom Azure RBAC permission definition. Actions and DataActions cover different permission planes; NotActions/NotDataActions subtract from this role’s grants and are not deny assignments. AssignableScopes controls where the role may be assigned; actual role-assignment scopes determine where a principal receives access.
Security Context
Unauthorized changes can expand permissions for existing assignees (contextual T1098.003). Expanding AssignableScopes does not expand existing assignment scopes. Wildcard Actions is broad control-plane authority within applicable assignments, not automatic tenant-wide access or every data-plane permission. Approved role maintenance uses the same operation.
Log Source
Azure Activity Log, Administrative category, with operationName.value: Microsoft.Authorization/roleDefinitions/write. This page’s title is a catalog label for the ARM operation, not the similarly named Entra RoleManagement audit activity. Creation and update share the same operation name; use result, resource history, and prior state to distinguish them. Request/response bodies are not guaranteed in Activity Log exports.
Key Fields
| Field | Investigation value |
|---|---|
operationName.value, resourceId | ARM role-definition write operation and definition ID. |
properties.requestbody, properties.responseBody | Definition if included; payload presence is not guaranteed. |
status, correlationId, operationId | Recorded result and related operation records. |
What to Investigate
- Confirm the recorded outcome and match the initiating identity, target, and timing to an approved change.
- Recover the prior and resulting definitions and compare all permission arrays and assignment eligibility scopes.
- Enumerate actual role assignments, their scopes, conditions, and applicable deny assignments; do not infer effective access from the role name.
- Correlate role assignments and subsequent resource operations before claiming escalation or data theft.
Sample Event
Synthetic scenario. The sample submits wildcard control-plane Actions and a subscription in AssignableScopes. It contains no prior definition or assignment inventory, so subscription-wide access for existing holders is not established.
Exact field presence, target ordering, modified-property names, and payload serialization remain unverified against captured logs. Treat these examples as illustrations, not guaranteed schemas or complete change histories.
{ "authorization": { "action": "Microsoft.Authorization/roleDefinitions/write", "scope": "/subscriptions/20000000-0000-4000-8000-000000000001/providers/Microsoft.Authorization/roleDefinitions/50000000-0000-4000-8000-000011101110" }, "caller": "draco@fantasticlogs.cloud", "channels": "Operation", "claims": { "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46", "ipaddr": "203.0.113.66", "name": "Draco Malfoy", "http://schemas.microsoft.com/identity/claims/objectidentifier": "30000000-0000-4000-8000-001010011010", "puid": "1003200000000666", "http://schemas.microsoft.com/identity/claims/tenantid": "10000000-0000-4000-8000-000000000001", "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "draco@fantasticlogs.cloud", "http://schemas.microsoft.com/identity/claims/wids": "e8611ab8-c189-46e8-94e1-60213ab1f814", "uti": "rdUpd231ExampleUtid01", "ver": "1.0" }, "correlationId": "90000000-0000-4000-8000-000100100000", "description": "", "eventDataId": "90000000-0000-4000-8000-000100100001", "eventName": { "value": "EndRequest", "localizedValue": "End request" }, "category": { "value": "Administrative", "localizedValue": "Administrative" }, "eventTimestamp": "2026-04-15T18:21:04.5128072Z", "level": "Informational", "operationId": "90000000-0000-4000-8000-000100111100", "operationName": { "value": "Microsoft.Authorization/roleDefinitions/write", "localizedValue": "Update role definition" }, "resourceGroupName": "", "resourceProviderName": { "value": "Microsoft.Authorization", "localizedValue": "Microsoft.Authorization" }, "resourceType": { "value": "Microsoft.Authorization/roleDefinitions", "localizedValue": "Microsoft.Authorization/roleDefinitions" }, "resourceId": "/subscriptions/20000000-0000-4000-8000-000000000001/providers/Microsoft.Authorization/roleDefinitions/50000000-0000-4000-8000-000011101110", "status": { "value": "Succeeded", "localizedValue": "Succeeded" }, "subStatus": { "value": "OK", "localizedValue": "OK (HTTP Status Code: 200)" }, "submissionTimestamp": "2026-04-15T18:21:05.1288014Z", "subscriptionId": "20000000-0000-4000-8000-000000000001", "tenantId": "10000000-0000-4000-8000-000000000001", "properties": { "statusCode": "OK", "serviceRequestId": null, "eventCategory": "Administrative", "entity": "/subscriptions/20000000-0000-4000-8000-000000000001/providers/Microsoft.Authorization/roleDefinitions/50000000-0000-4000-8000-000011101110", "message": "Microsoft.Authorization/roleDefinitions/write", "hierarchy": "10000000-0000-4000-8000-000000000001/20000000-0000-4000-8000-000000000001", "requestbody": "{\"name\":\"50000000-0000-4000-8000-000011101110\",\"properties\":{\"roleName\":\"Demiguise-MLOps-Operator\",\"description\":\"ML pipeline operator role\",\"assignableScopes\":[\"/subscriptions/20000000-0000-4000-8000-000000000001\"],\"permissions\":[{\"actions\":[\"*\"],\"notActions\":[],\"dataActions\":[],\"notDataActions\":[]}]}}" }, "relatedEvents": []}Sources
MITRE ATT&CK Mapping
Tactics: Privilege Escalation Persistence
- T1098.003 — Additional Cloud Roles — An adversary may add additional roles or permissions to an adversary-controlled cloud account to maintain persistent access to a tenant. For example, adversaries may update IAM policies in cloud-based environments or add a new global administrator in Office 365 environments. With sufficient permi...